Oracle XSQL servlet 1.0.3.0 and earlier allows remote attackers to execute arbitrary Java code by redirecting the XSQL server to another source via the xml-stylesheet parameter in the xslt stylesheet.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Oracle8i | Oracle | 8.1.7 (including) | 8.1.7 (including) |