vendor:
Oracle Document Capture
by:
Alexey Sintsov
N/A
CVSS
N/A
Insecure READ method
Unknown
CWE
Product Name: Oracle Document Capture
Affected Version From: 10.1350.0005
Affected Version To: 10.1350.0005
Patch Exists: NO
Related CWE: CVE-2010-3595
CPE: a:oracle:document_capture:10.1350.0005
Platforms Tested:
2010
Oracle Document Capture Insecure READ method
EasyMail ActiveX Control (emsmtp.dll) that included into Oracle Document Capture distrib can be used to read any file in the target system. Vulnerable method is "ImportBodyText()".
Mitigation:
Unknown