Vulnerability Name: | CVE-2000-0169 (CCN-4198) | ||||||||
Assigned: | 2000-03-15 | ||||||||
Published: | 2000-03-15 | ||||||||
Updated: | 2008-09-10 | ||||||||
Summary: | Batch files in the Oracle web listener ows-bin directory allow remote attackers to execute commands via a malformed URL that includes '?&'. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Tue Mar 14 2000 - 18:21:04 CST Oracle Web Listener 4.0.x Source: NTBUGTRAQ Type: UNKNOWN 20000314 Oracle Web Listener 4.0.x Source: MITRE Type: CNA CVE-2000-0169 Source: CCN Type: Oracle Technology Network Web site Oracle Application Server Security Issue Source: CCN Type: OSVDB ID: 264 Oracle Web Listener /ows-bin/ Directory Arbitrary Command Execution Source: BID Type: UNKNOWN 1053 Source: CCN Type: BID-1053 Oracle Web Listener Batch File Vulnerability Source: CCN Type: @stake, Inc./Cerberus Information Security Advisory CISADV000315 Oracle Web Listener remote command execution Source: XF Type: UNKNOWN oracle-weblistener-remote-attack(4198) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |