5
CVSSv2

CVE-2002-1089

Published: 04/10/2002 Updated: 05/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

rwcgi60 CGI program in Oracle Reports Server, by design, provides sensitive information such as the full pathname, which could enable remote malicious users to use the information in additional attacks.

Vulnerable Product Search on Vulmon Subscribe to Product

oracle application server 9.0.2

oracle reports 6.0.8

oracle reports 6.0.8.19

Exploits

source: wwwsecurityfocuscom/bid/5262/info A problem with Reports Server could make it possible to gain sensitive information from the server Under some circumstances, Reports Server may yield sensitive information to unauthenticated remote users This information may include the system path, software installed on the vulnerable system, ...