vendor:
Oracle Database
by:
Andrea 'bunker' Purificato
8.8
CVSS
HIGH
Privilege Escalation
264
CWE
Product Name: Oracle Database
Affected Version From: 9i
Affected Version To: 10g
Patch Exists: YES
Related CWE: N/A
CPE: oracle:oracle_database
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2006
ctxsys.drvxtabc.create_tables exploit (9i/10g)
This exploit allows an unprivileged user to gain DBA permission by exploiting the Oracle ctxsys.drvxtabc.create_tables vulnerability. The exploit creates a function called OWN which grants DBA permission to the target user when executed.
Mitigation:
Oracle recommends that users apply the latest Critical Patch Update (CPU) as soon as possible.