vendor:
Database Server
by:
Sh2kerr (Digital Security)
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Database Server
Affected Version From: Oracle 10.1.0.2.0
Affected Version To: Oracle 10.1.0.2.0
Patch Exists: YES
Related CWE: N/A
CPE: a:oracle:database_server:10.1.0.2.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
Oracle 10g R1 xDb.XDB_PITRIG_PKG.PITRIG_TRUNCATE SQL Injection Exploit
This exploit allows an attacker to gain access to the password hashes of Oracle 10g R1 users. The exploit uses the XDB.XDB_PITRIG_PKG.PITRIG_TRUNCATE function to execute a malicious SQL statement that inserts the user_id, username, and password of all users into a table called SH2KERR. The attacker can then access the table to view the password hashes.
Mitigation:
Oracle recommends applying the January 2008 Critical Patch Update to mitigate this vulnerability.