安全公告:Oracle Forms 10g 未授权远程代码执行漏洞(CVE-2014-4278)
netspi.com | 漏洞 | CVE-2014-4278 | #rce | #web-security | #input-validation | #oracle | #cve-2014-4278 | #oracle-forms
摘要
Oracle Forms 10g 未对传入 ListenerServlet 的 ifip 参数做校验,未认证攻击者可在服务器上执行任意命令(CVE-2014-4278);Oracle E-Business Suite 12.0.6 至 12.2.4 版本同样受影响。
- CVE
- CVE-2014-4278
- 发布时间
- 收录时间
Skip to content