Description
Oracle 9i Application Server allows remote attackers to bypass access restrictions for configuration files via a direct request to the XSQL Servlet (XSQLServlet).
Remediation
References
Related Vulnerabilities
Moodle Resource Management Errors Vulnerability (CVE-2015-2268)
Liferay Portal Incorrect Authorization Vulnerability (CVE-2024-25604)
WordPress Plugin Download Manager Multiple Cross-Site Scripting Vulnerabilities (3.2.48)
Ampache Improper Link Resolution Before File Access ('Link Following') Vulnerability (CVE-2008-3929)