Unrated severityNVD Advisory· Published Mar 22, 2007· Updated Apr 23, 2026
CVE-2007-1609
CVE-2007-1609
Description
Cross-site scripting (XSS) vulnerability in servlet/Spy in Dynamic Monitoring Services (DMS) in Oracle Application Server (OAS) 10g 10.1.2.0.0 allows remote attackers to inject arbitrary web script or HTML via the table parameter. NOTE: This may be related to CVE-2002-0563.
Affected products
2- cpe:2.3:a:oracle:application_server:10.1.2.0.0:*:*:*:*:*:*:*
- Range: =10.1.2.0.0
Patches
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- secunia.com/advisories/24554nvd
- securityreason.com/securityalert/2474nvd
- www.osvdb.org/33521nvd
- www.securityfocus.com/archive/1/463285/100/0/threadednvd
- www.securityfocus.com/archive/1/496045/100/0/threadednvd
- www.securityfocus.com/bid/23102nvd
- www.vupen.com/english/advisories/2007/1078nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/33146nvd
News mentions
0No linked articles in our index yet.