Oracle XSQL servlet 1.0.3.0 and earlier allows remote attackers to execute arbitrary Java code by redirecting the XSQL server to another source via the xml-stylesheet parameter in the xslt stylesheet.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2001-05-07T04:00:00
Updated: 2024-08-08T04:06:55.338Z
Reserved: 2001-02-06T00:00:00
Link: CVE-2001-0126
Vulnrichment
No data.
NVD
Status : Modified
Published: 2001-03-12T05:00:00.000
Modified: 2024-11-20T23:34:39.833
Link: CVE-2001-0126
Redhat
No data.