vendor:
Oracle Database XE
by:
MC, David Litchfield <david@ngssoftware.com>
N/A
CVSS
N/A
Buffer Overflow
119
CWE
Product Name: Oracle Database XE
Affected Version From: 9.2.0.1
Affected Version To: 9.2.0.1
Patch Exists: NO
Related CWE: CVE-2003-0727
CPE: oracle:9.2.0.1
Platforms Tested: Windows
2003
Oracle 9i XDB FTP UNLOCK Overflow (win32)
By passing an overly long token to the UNLOCK command, a stack based buffer overflow occurs. David Litchfield, has illustrated multiple vulnerabilities in the Oracle 9i XML Database (XDB), during a seminar on "Variations in exploit methods between Linux and Windows" presented at the Blackhat conference. Oracle9i includes a number of default accounts, including dbsnmp:dbsmp, scott:tiger, system:manager, and sys:change_on_install.
Mitigation:
Unknown