8.5
CVSSv2

CVE-2004-1364

Published: 04/08/2004 Updated: 19/10/2018
CVSS v2 Base Score: 8.5 | Impact Score: 10 | Exploitability Score: 6.8
VMScore: 860
Vector: AV:N/AC:M/Au:S/C:C/I:C/A:C

Vulnerability Summary

Directory traversal vulnerability in extproc in Oracle 9i and 10g allows remote malicious users to access arbitrary libraries outside of the $ORACLE_HOME\bin directory.

Vulnerable Product Search on Vulmon Subscribe to Product

oracle oracle10g standard 9.0.4 .0

oracle oracle8i standard 8.1.7 .4

oracle oracle9i standard 9.0.2

oracle oracle9i standard 9.0.1.4

oracle collaboration suite release 1

oracle application server 9.0.2.1

oracle oracle8i enterprise 8.1.6 .0.0

oracle oracle9i personal 8.1.7

oracle application server

oracle oracle9i client 9.2.0.2

oracle application server 9.0.2.0.0

oracle e-business suite 11.5.5

oracle oracle9i client 9.2.0.1

oracle enterprise manager 9.0.1

oracle oracle9i enterprise 9.2.0.5

oracle oracle9i personal 9.2.0.1

oracle oracle9i personal 9.2.0.2

oracle oracle9i personal 9.2.0.5

oracle oracle8i standard 8.0.6

oracle application server 9.0.4

oracle e-business suite 11.5.4

oracle oracle8i enterprise 8.1.5 .1.0

oracle oracle9i personal 9.0.1.5

oracle oracle10g personal 10.1 .0.2

oracle oracle8i standard 8.1.6

oracle oracle9i standard 9.0.1

oracle oracle9i standard 9.2.0.3

oracle oracle9i enterprise 9.2.0.2

oracle oracle9i enterprise 9.2.0.4

oracle oracle9i enterprise 9.0.1.5

oracle oracle9i personal 9.2

oracle oracle9i standard 9.0

oracle application server 9.0.2.3

oracle e-business suite 11.5.2

oracle application server 9.0.4.1

oracle e-business suite 11.5.7

oracle oracle9i standard 9.2.0.1

oracle application server 9.0.2.0.1

oracle oracle10g personal 9.0.4 .0

oracle oracle9i standard 9.2

oracle application server 9.0.4.0

oracle e-business suite 11.5.1

oracle oracle9i enterprise 9.0.1

oracle oracle9i standard 9.0.1.2

oracle oracle9i standard 9.2.0.4

oracle oracle9i enterprise 9.2.0

oracle enterprise manager 9

oracle oracle9i standard 9.2.0.5

oracle oracle8i standard 8.1.7 .1

oracle oracle8i enterprise 8.1.7 .1.0

oracle oracle8i enterprise 8.1.5 .0.2

oracle oracle8i enterprise 8.1.6 .1.0

oracle oracle9i standard 8.1.7

oracle oracle9i enterprise 8.1.7

oracle application server 9.0.2.2

oracle oracle10g standard 10.1 .0.2

oracle application server 9.0.2

oracle oracle9i personal 9.0.1

oracle oracle8i enterprise 8.1.7 .0.0

oracle e-business suite 11.5.8

oracle oracle8i standard 8.0.6 .3

oracle oracle9i standard 9.0.1.3

oracle application server 9.0.3

oracle oracle9i personal 9.2.0.4

oracle oracle8i standard 8.1.7 .0.0

oracle oracle9i standard 9.2.0.2

oracle oracle8i enterprise 8.1.7 .4

oracle application server 9.0.3.1

oracle oracle10g enterprise 10.1.0.2

oracle oracle9i enterprise 9.2.0.3

oracle enterprise manager grid control 10.1.0.2

oracle e-business suite 11.5.9

oracle enterprise manager database control 10.1.2

oracle oracle9i personal 9.0.1.4

oracle oracle10g enterprise 9.0.4 .0

oracle oracle9i personal 9.2.0.3

oracle oracle8i enterprise 8.0.6 .0.0

oracle e-business suite 11.5.6

oracle e-business suite 11.5.3

oracle oracle8i enterprise 8.1.5 .0.0

oracle oracle9i enterprise 9.2.0.1

oracle oracle8i standard 8.1.7

oracle oracle9i standard 9.0.1.5

oracle oracle8i enterprise 8.0.6 .0.1

oracle oracle8i enterprise 8.0.5 .0.0

oracle oracle8i standard 8.1.5

oracle oracle9i enterprise 9.0.1.4

Exploits

This PL/SQL code exploits the Oracle extproc directory traversal bug to remotely execute arbitrary OS commands with the privileges of the DBMS user All versions of Oracle 9i are susceptible Oracle 10g versions prior to 10103 are susceptible ...
-- -- $Id: raptor_oraextprocsql,v 11 2006/12/19 14:21:00 raptor Exp $ -- -- raptor_oraextprocsql - command exec via oracle extproc -- Copyright (c) 2006 Marco Ivaldi <raptor@0xdeadbeefinfo> -- -- Directory traversal vulnerability in extproc in Oracle 9i and 10g -- allows remote attackers to access arbitrary libraries outside of the -- $ ...
source: wwwsecurityfocuscom/bid/10871/info Reportedly, multiple unspecified Oracle products contain multiple unspecified vulnerabilities The reported vulnerabilities include SQL-injection issues, buffer-overflow issues, and others There have also been reports that issues covered in this BID and resolved in the referenced Oracle patc ...