The grid option in PeopleSoft 8.42 stores temporary .xls files in guessable directories under the web document root, which allows remote attackers to steal search results by directly accessing the files via a URL request.
References
Link | Resource |
---|---|
http://marc.info/?l=bugtraq&m=106554919000847&w=2 | Mailing List |
http://marc.info/?l=bugtraq&m=106554919000847&w=2 | Mailing List |
Configurations
History
20 Nov 2024, 23:45
Type | Values Removed | Values Added |
---|---|---|
References | () http://marc.info/?l=bugtraq&m=106554919000847&w=2 - Mailing List |
Information
Published : 2003-11-17 05:00
Updated : 2024-11-20 23:45
NVD link : CVE-2003-0841
Mitre link : CVE-2003-0841
CVE.ORG link : CVE-2003-0841
JSON object : View
Products Affected
oracle
- peopletools
CWE