Directory traversal vulnerability in PL/SQL Apache module in Oracle Oracle 9i Application Server allows remote attackers to access sensitive information via a double encoded URL with .. (dot dot) sequences.Referenceshttp://www.securityfocus.com/bid/3727http://www.kb.cert.org/vuls/id/758483http://www.iss.net/security_center/static/7728.phphttp://otn.oracle.com/deploy/security/pdf/modplsql.pdfhttp://www.securityfocus.com/archive/1/246663