CVE-2005-2372

Oracle Forms 4.5 through 10g starts form executables from arbitrary directories and executes them as the Oracle or System user, which allows attackers to execute arbitrary code by uploading a malicious .fmx file and referencing it using an absolute pathname argument in the (1) form or (2) module parameters to f90servlet.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:oracle:forms:10g:*:*:*:*:*:*:*
cpe:2.3:a:oracle:forms:3.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:forms:6.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:forms:6i:*:*:*:*:*:*:*
cpe:2.3:a:oracle:forms:9i:*:*:*:*:*:*:*
cpe:2.3:a:oracle:forms:4.5:*:*:*:*:*:*:*
cpe:2.3:a:oracle:forms:5.0:*:*:*:*:*:*:*

Information

Published : 2005-07-25 21:00

Updated : 2016-10-17 20:26


NVD link : CVE-2005-2372

Mitre link : CVE-2005-2372


JSON object : View

Advertisement

dedicated server usa

Products Affected

oracle

  • forms