5.5
CVSSv2

CVE-2008-3984

Published: 14/10/2008 Updated: 08/08/2017
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
VMScore: 555
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N

Vulnerability Summary

Unspecified vulnerability in the Workspace Manager component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.3, and 11.1.0.6 allows remote authenticated users to affect confidentiality and integrity, related to SYS.LT and WMSYS.LT, a different vulnerability than CVE-2008-3982 and CVE-2008-3983.

Vulnerable Product Search on Vulmon Subscribe to Product

oracle database 9i 9.2.0.8dv

oracle database 10g 10.1.0.5

oracle database 10g 10.2.0.3

oracle database 11i 11.1.0.6

oracle database 9i 9.2.0.8

Exploits

/*********************************************************/ /*Oracle 10g SYSLTREMOVEWORKSPACE SQL Injection Exploit*/ /****grant DBA and create new OS user (advanced extproc)*/ /*********************************************************/ /***********exploit grant DBA to scott********************/ /***********and execute OS command "net user"***** ...