CVE-2005-4550 describes a vulnerability in the Oracle Application Server (OracleAS) Discussion Forum Portlet, specifically within the PORTAL schema. Remote attackers can exploit this flaw by manipulating the df_next_page parameter with a trailing null byte, allowing them to retrieve the source code of arbitrary JSP and other files. This vulnerability has a CVSS score of 5.0, indicating a medium severity with a network-based attack vector, low attack complexity, and potential for partial confidentiality impact. While there is no evidence of active exploitation or Metasploit/Nuclei modules, an ExploitDB entry exists, and despite its age, it has a high FAUCET Risk Score and a relatively high EPSS score, suggesting a non-trivial potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:oracle:application_server_discussion_forum_portlet:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.