Batch files in the Oracle web listener ows-bin directory allow remote attackers to execute commands via a malformed URL that includes ?&.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Application_server | Oracle | 4.0 (including) | 4.0 (including) |
References