.. / CVE-2018-3238

Exploit for Oracle Fusion Middleware WebCenter Sites 11.1.1.8.0 - Cross-Site Scripting (CVE-2018-3238)

Description:

The Oracle WebCenter Sites 11.1.1.8.0 component of Oracle Fusion Middleware is impacted by easily exploitable cross-site scripting vulnerabilities that allow high privileged attackers with network access via HTTP to compromise Oracle WebCenter Sites.

Nuclei Template

View the template here CVE-2018-3238.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2018/CVE-2018-3238.yaml
Copy

References:

https://nvd.nist.gov/vuln/detail/CVE-2018-3238
https://outpost24.com/blog/Vulnerabilities-discovered-in-Oracle-WebCenter-Sites
https://www.oracle.com/security-alerts/cpuoct2018.html
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
https://github.com/ARPSyndicate/kenzer-templates