← Vulnerability feed

Vulnerability record · CVE-2005-1381 · published 3 May 2005

CVE-2005-1381: Oracle application server web cache vulnerability

Oracle · Application Server Web Cache

Multiple cross-site scripting (XSS) vulnerabilities in Oracle Webcache 9i allow remote attackers to inject arbitrary web script or HTML via the (1) cache_dump_file or (2) PartialPageErrorPage parameter.

6.8 CVSS 2.0 Medium EPSS 20% · top 2.6%
6.8CVSS 2.0 base score
20%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References, 6 tagged exploit
16 Jun 2026Last modified by NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in Oracle Webcache 9i allow remote attackers to inject arbitrary web script or HTML via the (1) cache_dump_file or (2) PartialPageErrorPage parameter.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-1381 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2004-0385Oracle application server web cache vulnerabilityHeap-based buffer overflow in Oracle 9i Application Server Web Cache 9.0.4.0.0, 9.0.3.1.0, 9.0.2.3.0, and 9.0.0.4.0 allows remote attackers to execut…EPSS 16%10.0CVE-2002-1641Oracle application server web cache vulnerabilityMultiple buffer overflows in Oracle Web Cache for Oracle 9i Application Server (9iAS) allow remote attackers to execute arbitrary code via unknown ve…EPSS 9.1%7.5CVE-2002-0559Oracle application server vulnerabilityBuffer overflows in PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allow remote attackers to cause a denial of service or execute ar…EPSS 13%7.5CVE-2002-0561Oracle application server vulnerabilityThe default configuration of the PL/SQL Gateway web administration interface in Oracle 9i Application Server 1.0.2.x uses null authentication, which …EPSS 9.7%7.5CVE-2002-0564Oracle application server vulnerabilityPL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to bypass authentication for a Database Access Descriptor (DA…EPSS 5.1%7.5CVE-2001-0836Oracle application server web cache vulnerabilityBuffer overflow in Oracle9iAS Web Cache 2.0.0.1 allows remote attackers to execute arbitrary code via a long HTTP GET request.EPSS 15%5.0CVE-2005-1382Oracle application server web cache vulnerabilityThe webcacheadmin module in Oracle Webcache 9i allows remote attackers to corrupt arbitrary files via a full pathname in the cache_dump_file paramete…EPSS 7.0%5.0CVE-2002-0560Oracle application server vulnerabilityPL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to obtain sensitive information via the OWA_UTIL stored proce…EPSS 3.7%

Source: NIST National Vulnerability Database (record CVE-2005-1381), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.