putosoft softputo

3 exploits Active since Dec 2006
CVE-2006-6703 EXPLOITDB text WORKING POC
Oracle Portal <10g - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Oracle Portal 9i and 10g allow remote attackers to inject arbitrary JavaScript via the tc parameter in webapp/jsp/container_tabs.jsp, and other unspecified vectors.
EIP-2026-103613 EXPLOITDB text WRITEUP
Oracle 10g - Alter Session Integer Overflow
CVE-2006-6697 EXPLOITDB text WORKING POC
Oracle Portal <10g - CRLF Injection
CRLF injection vulnerability in webapp/jsp/calendar.jsp in Oracle Portal 10g and earlier, including 9.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the enc parameter.