vendor:
Oracle Database
by:
Alexandr 'Sh2kerr' Polyakov
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Oracle Database
Affected Version From: Oracle 10g
Affected Version To: Oracle 10g
Patch Exists: NO
Related CWE:
CPE: a:oracle:oracle_database:10g
Platforms Tested: Oracle 10.1.0.2.0
2007
Oracle 10g CTX_DOC.MARKUP SQL Injection Exploit
This exploit allows an attacker to grant DBA privileges to an unprivileged user in Oracle 10g by exploiting the CTX_DOC.MARKUP function. The exploit involves creating a function called HACKIT that executes a dynamic SQL statement to grant the DBA role to the user 'scott'. The function is then called, granting the DBA role to the user. This vulnerability was reported by David Litchfield in June 2005 and was publicly disclosed on October 17, 2007. This exploit has been tested on Oracle 10.1.0.2.0.
Mitigation:
To mitigate this vulnerability, it is recommended to apply the necessary patches provided by Oracle. Additionally, it is important to regularly update and apply security patches to all Oracle software installations.