The grid option in PeopleSoft 8.42 stores temporary .xls files in guessable directories under the web document root, which allows remote attackers to steal search results by directly accessing the files via a URL request.
References
Link | Resource |
---|---|
http://marc.info/?l=bugtraq&m=106554919000847&w=2 | Mailing List |
Configurations
Information
Published : 2003-11-16 21:00
Updated : 2019-08-19 08:38
NVD link : CVE-2003-0841
Mitre link : CVE-2003-0841
JSON object : View
CWE
Products Affected
oracle
- peopletools