Oracle WebCenter Sites (MOSC)

MOSC Banner

HTTP Headers SQL injection

edited Mar 15, 2014 12:00PM in Oracle WebCenter Sites (MOSC) 1 commentAnswered

Hello Guys, we are running WebCenter Sites 11gR1 11.1.1.8.0 with patch 3 installed. We have ran a security check across all the pages of our site,and several vulnerabilities related to HTTP Header SQL injection have shown up:

SQL Injection In HTTP Header

It has been detected by exploiting the parameter WT_FPC

It has been detected by exploiting the parameter JSESSIONID

It has been detected by exploiting the parameter referer

It has been detected by exploiting the parameter user-agent

We currently are NOT operating using any cookies/headers values, so I'd suspect that this has to do with security settings for the CMS. Can anyone point me in the right direction regarding how to solve these issues?

Tagged:

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center