vendor:
Oracle Database
by:
Marco Ivaldi
7.5
CVSS
HIGH
Directory traversal vulnerability in extproc in Oracle 9i and 10g
22
CWE
Product Name: Oracle Database
Affected Version From: Oracle 9i
Affected Version To: Oracle 10g versions prior to 10.1.0.3
Patch Exists: NO
Related CWE: CVE-2004-1364
CPE: a:oracle:oracle_database
Platforms Tested: Solaris 9 and 10
2006
raptor_oraextproc.sql
This PL/SQL code exploits the Oracle extproc directory traversal bug to remotely execute arbitrary OS commands with the privileges of the DBMS user (the CREATE [ANY] LIBRARY privilege is needed).
Mitigation:
Apply patches provided by Oracle