Subscribe via feed.

Oracle Application Express AnyChart Flash-Based Cross Site Scripting

Posted by deepcore on January 4, 2019 – 6:35 am

Oracle Application Express versions prior to 5.1.4.00.08 suffer from a cross site scripting vulnerability. The vulnerability is located in the OracleAnyChart.swf file. User input passed through the “__externalobjid” GET parameter is not properly sanitized before being passed to the “ExternalInterface.call” method.


This post is under “exploit” and has no respond so far.
If you enjoy this article, make sure you subscribe to my RSS Feed.

Post a reply

You must be logged in to post a comment.