Oracle 10g Dynamic Monitoring Services XSS /servlet/Spy

Risk: Low
Local: No
Remote: Yes

CVSS Base Score: 4.3/10
Impact Subscore: 2.9/10
Exploitability Subscore: 8.6/10
Exploit range: Remote
Attack complexity: Medium
Authentication: No required
Confidentiality impact: None
Integrity impact: Partial
Availability impact: None

Hi, Access to http://somesite/servlet/Spy should be restricted. But generally database or system administrators ignore the hardening of Oracle apllications or database. I have noticed XSS bug in Dynamic Monitoring services on Oracle-Application-Server-10g/ http://somesite/servlet/Spy?format=metrictable&cache=false&interval=6400 000&table=%3Cscript%3Ealert('inTellectPRO')%3C/script%3E&orderby=Name d3nx

