CVE

Id
10541  
CVE No.
CVE-2004-2115  
Status
Candidate  
Description
Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTTP Server 1.3.22, based on Apache, allow remote attackers to execute arbitrary script as other users via the (1) action, (2) username, or (3) password parameters in an isqlplus request.  
Phase
Assigned (20050527)  
Votes
None (candidate not yet proposed)  
Comments