2. Cross-domain Referer leakage
Severity: | High |
Confidence: | Firm |
Host: | http://apex.oracle.com |
Path: | /pls/otn/f |
GET /pls/otn/f?p=42988:2' HTTP/1.1 Host: apex.oracle.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.202 Safari/535.1 Accept: text/html,application Referer: http://www.oracle.com/us Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_wgw_lv=1315343380912; s_nr6=1315343380933-New; s_cc=true; s_nr=1318816293527; gpw_e24=http%3A%2F%2Fwww |
HTTP/1.1 200 OK Date: Mon, 17 Oct 2011 01:55:05 GMT Server: Oracle-Application-Server Content-Length: 518 Content-Type: text/html; charset=UTF-8 Content-Language: en <table summary=""><tr><td><img src="/i/error.gif" border="0" /></td><td>Error</td><td ORA-06502: PL/SQL: numeric or value error: character to number conversion error</td> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://apex.oracle.com |
Path: | /pls/otn/f |
GET /pls/otn/f?p=42988:3 Host: apex.oracle.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.202 Safari/535.1 Accept: text/html,application Referer: http://www.oracle.com/us Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WWV_CUSTOM-F_5924477 |
HTTP/1.1 200 OK Date: Mon, 17 Oct 2011 01:51:15 GMT Server: Oracle-Application-Server Content-Length: 13203 Content-Type: text/html; charset=UTF-8 Content-Language: en <html lang="en-us" xmlns:htmldb="http:/ <head> <title>External Account Help Form</title> <link rel="stylesheet" href="/i/themes/theme_1 <link ...[SNIP]... <input type="hidden" name="p_request" value="" id="pRequest" /><img border="0" src="http://www.oracleimg ...[SNIP]... |