[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
CVE-2010-2404 | Persistent Cross Site Scripting Vulnerability in Oracle I-Recruitment - E-Business Suite
Advisory: Persistent Cross Site Scripting Vulnerability in Oracle I-Recruitment File Uploading Module- E-Business Suite
Version Affected - 126.96.36.199, 12.0.6, 12.1.3
About: Oracle I-Recruitment Suite
Oracle iRecruitment is a web based full-cycle recruiting solution that
gives managers, recruiters and candidates the ability to manage every
phase of finding, recruiting, hiring, and tracking new employees. It is a
part of Oracle E-business suite.
A persistent cross site scripting vulnerability exists in the I-Recruitment
portal. The account information page allows the user to upload his resume in
Microsoft Word document. An attacker can construct a malicious MSWord file to
conduct XSS attack by setting XSS payload in hyperlinks in order to bypass
For attack details , Refer to the following paper:
The vulnerability was disclosed to Oracle in January 2009 and is patched
in October 2010 CPU release.
Aditya K Sood of SecNiche Security
adi_ks [at] secniche.org
The information in the advisory is believed to be accurate at the time of
publishing based on currently available information. Use of the
information constitutes acceptance for use in an AS IS condition. There is
no representation or warranties, either express or implied by or with
respect to anything.