[<prev] [next>] [day] [month] [year] [list]
Message-ID: <f6d1ddc30703250819p6bc47917i357ff9c13b3860f6@mail.gmail.com>
Date: Sun, 25 Mar 2007 15:19:33 +0000
From: "handrix cobra" <handrix@...il.com>
To: full-disclosure@...ts.grok.org.uk, bugtraq@...urityfocus.com
Cc: simo@...x.org
Subject: Redirection vulnerability in oracle entreprise
manager
Product: Oracle Entreprise manager
Vulnerabilities: Phishing
Level: Medium
By: Handrix <handrix_at_morx_org>
25 March 2007
MorX security research team
www.morx.org
The oracle entreprise manager are vulnerable to phishing attack in help
rubric,
an attacker can redirect your login and password to an another malicious
website.
Any way feel free to verify the whole login page contenent before making
your sensible information on.
Other solution deactivate the help link
Simple request :
http://www.victimeserver.com:5500/em/console/help/fr/topic?inOHW=false&linkHelp=false&file=http://www.maliciousserver.dot:5500/em/console/
Version: Oracle entreprise manager 10g
May be others
Content of type "text/html" skipped
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists