[<prev] [next>] [day] [month] [year] [list]
Message-ID: <20061221211853.2585.qmail@securityfocus.com>
Date: 21 Dec 2006 21:18:53 -0000
From: majororacle@...il.com
To: bugtraq@...urityfocus.com
Subject: Re: Oracle Portal 10g HTTP Response Splitting
This also occurs in Portal 9.0.2 in the file calendar.jsp, calendarDialog.jsp, and fred.jsp, all of which are under the $ORACLE_HOME/j2ee directory in various locations. The offending code is
String enc = request.getParameter("enc");
if ((enc == null) || "".equals(enc))
response.setContentType("text/html");
else
response.setContentType("text/html;charset=" + enc);
which can be commented out as follows:
// String enc = request.getParameter("enc");
// if ((enc == null) || "".equals(enc))
response.setContentType("text/html");
// else
// response.setContentType("text/html;charset=" + enc);
Powered by blists - more mailing lists