PT-2005-3285 · Oracle · Oracle Reports
Alexander Kornbrust
·
Published
2005-07-26
·
Updated
2018-10-19
·
CVE-2005-2371
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Oracle Reports versions 6.0, 6i, 9i, 10g
Description
A directory traversal issue allows remote attackers to overwrite arbitrary files by manipulating the
desname parameter with sequences such as "..", Windows drive letters (e.g., "C:"), or absolute paths.Recommendations
For Oracle Reports versions 6.0, 6i, 9i, 10g, consider applying the fix provided in CPU Jan 2006, which likely addresses this issue.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oracle Reports