Batch files in the Oracle web listener ows-bin directory allow remote attackers to execute commands via a malformed URL that includes ?&.
Affected Software
| Name |
Vendor |
Start Version |
End Version |
| Application_server |
Oracle |
4.0 (including) |
4.0 (including) |
References