vendor:
Oracle Database
by:
Andrea "bunker" Purificato
7.5
CVSS
HIGH
Remote Code Execution
CWE
Product Name: Oracle Database
Affected Version From: Oracle Database 10g Enterprise Edition Release 10.1.0.3.0
Affected Version To: Oracle Database 10g
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Tested on Oracle Database 10g Enterprise Edition Release 10.1.0.3.0
2007
Remote Oracle KUPM$MCP.MAIN exploit (10g)
This exploit allows an attacker to grant or revoke dba permission to an unprivileged user in Oracle Database 10g. It uses an evil cursor injection technique to execute malicious code.
Mitigation:
Apply the necessary patches or updates provided by Oracle. Restrict privileges for unprivileged users.