First published: Sat Dec 23 2006(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Oracle Portal 9i and 10g allow remote attackers to inject arbitrary JavaScript via the tc parameter in webapp/jsp/container_tabs.jsp, and other unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Oracle9i | ||
Oracle Database 10g |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-6703 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To mitigate CVE-2006-6703, ensure that you are using the latest patched version of Oracle Portal and sanitize user inputs in applications.
CVE-2006-6703 affects Oracle Portal 9i and 10g applications that process the tc parameter in URLs.
The main attack vector for CVE-2006-6703 is via injecting arbitrary JavaScript through the tc parameter in specific JSP files.
Yes, CVE-2006-6703 can be exploited remotely by attackers to execute malicious scripts in the context of the victim's browser.