5
CVSSv2

CVE-2005-0701

Published: 07/03/2005 Updated: 18/10/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in Oracle Database Server 8i and 9i allows remote malicious users to read or rename arbitrary files via "\\.\\.." (modified dot dot backslash) sequences to UTL_FILE functions such as (1) UTL_FILE.FOPEN or (2) UTL_FILE.frename.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

oracle database server

Exploits

source: wwwsecurityfocuscom/bid/12749/info Oracle Database server is reported prone to multiple directory traversal vulnerabilities that may allow a remote attacker to read, write, or rename arbitrary files with the privileges of the Oracle Database server The issues are reported to exist due to a lack of sufficient input validation per ...