Description
Unspecified vulnerability in the Secure Enterprise Search component in Oracle Database 10.1.8.3 allows remote attackers to affect integrity via unknown vectors. NOTE: the previous information was obtained from the July 2009 CPU. Oracle has not commented on claims from an established researcher that this is cross-site scripting (XSS) via the search_p_groups parameter in search/query/search.
Remediation
References
Related Vulnerabilities
WordPress Plugin leads5050-visitor-insights Security Bypass (1.0.5)
Apache Tomcat CVE-2018-1305 Vulnerability (CVE-2018-1305)
WordPress Plugin Admin Management Xtended Privilege Escalation (2.4.0)
MongoDb Use After Free Vulnerability (CVE-2019-2393)
WordPress 4.8.x Possible SQL Injection Vulnerability (4.8 - 4.8.2)