vendor:
Oracle XML DB
by:
Unknown
5.5
CVSS
MEDIUM
Cross-Site Scripting
79
CWE
Product Name: Oracle XML DB
Affected Version From: Not mentioned
Affected Version To: Not mentioned
Patch Exists: YES
Related CWE: Not mentioned
CPE: Not mentioned
Platforms Tested:
2005
Cross-Site Scripting Vulnerability in Oracle XML DB
The vulnerability allows attackers to execute arbitrary script code in the browser of an unsuspecting user by injecting malicious input. This can lead to the theft of authentication credentials and other attacks.
Mitigation:
Oracle addressed this vulnerability in the April 2005 Critical Patch Update. Users should update to the latest version to mitigate this issue.