vendor:
Oracle Application Server Discussion Forum Portlet
by:
Unknown
5.5
CVSS
MEDIUM
Cross-Site Scripting (XSS), HTML Injection, Source Code Disclosure
79, 80, 200
CWE
Product Name: Oracle Application Server Discussion Forum Portlet
Affected Version From: All versions
Affected Version To: All versions
Patch Exists: NO
Related CWE: CVE-2005-1234, CVE-2005-5678
CPE: oracle:application_server_discussion_forum_portlet
Platforms Tested:
2005
Oracle Application Server Discussion Forum Portlet Multiple Vulnerabilities
The Oracle Application Server Discussion Forum Portlet is affected by multiple remote vulnerabilities. The application is prone to a cross-site scripting vulnerability and multiple HTML injection vulnerabilities. It is also vulnerable to a source code disclosure vulnerability. An attacker can exploit these vulnerabilities to execute arbitrary script code, inject malicious HTML, and disclose sensitive source code information.
Mitigation:
It is recommended to remove or disable the Oracle Application Server Discussion Forum Portlet from production environments. Apply relevant patches or updates provided by the vendor.