Batch files in the Oracle web listener ows-bin directory allow remote attackers to execute commands via a malformed URL that includes '?&'.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2000-0168
http://www.securityfocus.com/bid/1053
http://archives.neohapsis.com/archives/ntbugtraq/2000-q1/0211.html