Isql*plus In Oracle 10g Application Server Allo vulnerability report
vulnerabilities.aspcode.net
Phase:
ISQL*Plus in Oracle 10g Application Server allows remote attackers to execute arbitrary files via an absolute pathname in the file parameter to the load.uix script.
References
BUGTRAQ:Thursday, December 23, 2004 Oracle ISQLPlus file access vulnerability (#NISR2122004E) | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=110382264415387&w=2 | MISC:http://www.ngssoftware.com/advisories/oracle23122004E.txt | SUNALERT:101782 | URL:http://
Votes:
Assigned (Friday, January 07, 2005)
Comments:
None (candidate not yet proposed)
F7:
Tagged as
Application
ISQL*Plus
arbitrary
attackers
parameter
absolute
pathname
loaduix
execute
Server
Oracle
script
allows
remote
files
file
via
10g