CVE-2002-0386
Oracle9iAS 9.0.2 - Denial of Service via Dot-Dot Sequence or Malformed Chunked Encoding
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2002-0386. PoCs published by @stake.
AI-analyzed exploit summary This exploit demonstrates a denial-of-service (DoS) vulnerability in Oracle 9i Application Server (9iAS) on Windows by sending malformed HTTP requests to the Web Administration module, causing the server to crash.
Description
The administration module for Oracle Web Cache in Oracle9iAS (9i Application Suite) 9.0.2 allows remote attackers to cause a denial of service (crash) via (1) an HTTP GET request containing a ".." (dot dot) sequence, or (2) a malformed HTTP GET request with a chunked Transfer-Encoding with missing data.
Exploits (1)
This exploit demonstrates a denial-of-service (DoS) vulnerability in Oracle 9i Application Server (9iAS) on Windows by sending malformed HTTP requests to the Web Administration module, causing the server to crash.