Description
Batch files in the Oracle web listener ows-bin directory allow remote attackers to execute commands via a malformed URL that includes '?&'.
Remediation
References
Related Vulnerabilities
WordPress Plugin Form Manager Remote Command Execution (1.7.2)
WordPress Plugin Fast Secure Contact Form 'index.php' Cross-Site Scripting (3.0.3.1)
Roundcube Unspesificed Vulnerability (CVE-2019-10740)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-5478)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-1159)