vendor:
Oracle Database
by:
N1V1Hd $3c41r3
9
CVSS
HIGH
Privilege Escalation
264
CWE
Product Name: Oracle Database
Affected Version From: 10.2.0.2.0
Affected Version To: 10.2.0.2.0
Patch Exists: YES
Related CWE: N/A
CPE: oracle:oracle_database:10.2.0.2.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2006
Oracle 10g 10.2.0.2.0 Exploit
This exploit grants DBA privileges to the hacker by exploiting a vulnerability in the Oracle 10g 10.2.0.2.0 database. The exploit uses the SYS.DBMS_EXPORT_EXTENSION.GET_DOMAIN_INDEX_METADATA function to execute a malicious code which grants DBA privileges to the hacker.
Mitigation:
Oracle recommends that customers apply the latest Critical Patch Update (CPU) as it contains fixes for security vulnerabilities. Additionally, customers should apply the latest Patch Set Update (PSU) as it contains a superset of all fixes from the latest CPU.