SecurityAlert : 2474 CVE : CVE-2007-1609 SecurityRisk : Low (About) Remote Exploit : Yes Local Exploit : No Exploit Available : Yes Credit : Sea Shark (sead3nx gmail com) Published : 26.03.2007
Affected Software :
Oracle 10g Dynamic Monitoring Services
Advisory Content :
Hi,
Access to http://somesite/servlet/Spy should be restricted. But
generally database or system administrators ignore the hardening of
Oracle apllications or database. I have noticed XSS bug in Dynamic
Monitoring services on Oracle-Application-Server-10g/10.1.2.0.0.
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.