CVE-2002-0386

Oracle9iAS 9.0.2 - Denial of Service via Dot-Dot Sequence or Malformed Chunked Encoding

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2002-0386. PoCs published by @stake.

AI-analyzed exploit summary This exploit demonstrates a denial-of-service (DoS) vulnerability in Oracle 9i Application Server (9iAS) on Windows by sending malformed HTTP requests to the Web Administration module, causing the server to crash.

Description

The administration module for Oracle Web Cache in Oracle9iAS (9i Application Suite) 9.0.2 allows remote attackers to cause a denial of service (crash) via (1) an HTTP GET request containing a ".." (dot dot) sequence, or (2) a malformed HTTP GET request with a chunked Transfer-Encoding with missing data.

Exploits (1)

exploitdb WORKING POC VERIFIED
by @stake · textdosmultiple
https://www.exploit-db.com/exploits/21911

This exploit demonstrates a denial-of-service (DoS) vulnerability in Oracle 9i Application Server (9iAS) on Windows by sending malformed HTTP requests to the Web Administration module, causing the server to crash.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Oracle 9i Application Server (9iAS) on Microsoft Windows
No auth needed
Prerequisites: Network access to the Oracle 9iAS Web Administration module
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/10284.php
Exploit, Patch, Vendor Advisory vendor-advisory x_refsource_atstake
http://www.atstake.com/research/advisories/2002/a102802-1.txt
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/5902
Patch, Vendor Advisory x_refsource_confirm
http://otn.oracle.com/deploy/security/pdf/2002alert43rev1.pdf

Scores

EPSS 0.2198
EPSS Percentile 97.4%

Details

Status published
Products (1)
oracle/application_server 9.0.2
Published Nov 04, 2002
Tracked Since Feb 18, 2026