Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2005-2371

Опубликовано: 26 июл. 2005
Источник: nvd
CVSS2: 5
EPSS Низкий

Описание

Directory traversal vulnerability in Oracle Reports 6.0, 6i, 9i, and 10g allows remote attackers to overwrite arbitrary files via (1) "..", (2) Windows drive letter (C:), and (3) absolute path sequences in the desname parameter. NOTE: this issue was probably fixed by REP06 in CPU Jan 2006, in which case it overlaps CVE-2006-0289.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:oracle:reports:6.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:reports:6i:*:*:*:*:*:*:*
cpe:2.3:a:oracle:reports:9i:*:*:*:*:*:*:*
cpe:2.3:a:oracle:reports:10g:*:*:*:*:*:*:*

EPSS

Процентиль: 88%
0.03626
Низкий

5 Medium

CVSS2

Дефекты

CWE-22

Связанные уязвимости

github
почти 4 года назад

Directory traversal vulnerability in Oracle Reports 6.0, 6i, 9i, and 10g allows remote attackers to overwrite arbitrary files via (1) "..", (2) Windows drive letter (C:), and (3) absolute path sequences in the desname parameter. NOTE: this issue was probably fixed by REP06 in CPU Jan 2006, in which case it overlaps CVE-2006-0289.

EPSS

Процентиль: 88%
0.03626
Низкий

5 Medium

CVSS2

Дефекты

CWE-22