CVE-2005-3202
published 2005-10-14CVE-2005-3202: Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTML DB (HTMLDB) 1.3 through 1.3.6 allow remote attackers to inject arbitrary web script or HTML…
PriorityP429medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EXPLOIT
EPSS
10.98%
95.3th percentile
Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTML DB (HTMLDB) 1.3 through 1.3.6 allow remote attackers to inject arbitrary web script or HTML, and subsequently execute SQL statements via the (1) p or (2) p_t02 parameters.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | html_db | — | — |
| oracle | html_db | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
Oracle HTML DB 1.5/1.6 - 'wwv_flow.accept?p_t02' Cross-Site Scripting
exploitdb·2005-10-07
CVE-2005-3202 Oracle HTML DB 1.5/1.6 - 'wwv_flow.accept?p_t02' Cross-Site Scripting
Oracle HTML DB 1.5/1.6 - 'wwv_flow.accept?p_t02' Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/15031/info
Oracle HTML DB is prone to cross-site scripting vulnerabilities.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.
An attacker can leverage these issues to execute SQL statements in the context of an affected user as well.
These issues was originally described and addressed in Oracle Critical Patch Update - April 2005, BID 13139 (Oracle Multiple Vulnerabilities). Due to the availability of more information, these issues are being assigned a separate BID.
http://www.example.com/pls/otn/wwv_flow.accept?p_flow_id=4500&p_flow_step_id=3&p_instance=42857654227503
Exploit-DB
Oracle HTML DB 1.5/1.6 - 'f?p=' Cross-Site Scripting
exploitdb·2005-10-07
CVE-2005-3202 Oracle HTML DB 1.5/1.6 - 'f?p=' Cross-Site Scripting
Oracle HTML DB 1.5/1.6 - 'f?p=' Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/15031/info
Oracle HTML DB is prone to cross-site scripting vulnerabilities.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.
An attacker can leverage these issues to execute SQL statements in the context of an affected user as well.
These issues was originally described and addressed in Oracle Critical Patch Update - April 2005, BID 13139 (Oracle Multiple Vulnerabilities). Due to the availability of more information, these issues are being assigned a separate BID.
http://www.example.com/pls/otn/f?p=4500:alert(document.cookie);59:3239664590547916206
No writeups or analysis indexed.
http://archives.neohapsis.com/archives/fulldisclosure/2005-10/0173.htmlhttp://marc.info/?l=bugtraq&m=112870398418456&w=2http://secunia.com/advisories/14935/http://securityreason.com/securityalert/62http://www.oracle.com/technology/deploy/security/pdf/cpuapr2005.pdfhttp://www.osvdb.org/20051http://www.osvdb.org/20052http://www.red-database-security.com/advisory/oracle_htmldb_css.htmlhttp://www.securityfocus.com/bid/15031https://exchange.xforce.ibmcloud.com/vulnerabilities/22540http://archives.neohapsis.com/archives/fulldisclosure/2005-10/0173.htmlhttp://marc.info/?l=bugtraq&m=112870398418456&w=2http://secunia.com/advisories/14935/http://securityreason.com/securityalert/62http://www.oracle.com/technology/deploy/security/pdf/cpuapr2005.pdfhttp://www.osvdb.org/20051http://www.osvdb.org/20052http://www.red-database-security.com/advisory/oracle_htmldb_css.htmlhttp://www.securityfocus.com/bid/15031https://exchange.xforce.ibmcloud.com/vulnerabilities/22540
2005-10-14
Published