Логотип exploitDog
bind:CVE-2005-2372
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2005-2372

Количество 2

Количество 2

nvd логотип

CVE-2005-2372

больше 20 лет назад

Oracle Forms 4.5 through 10g starts form executables from arbitrary directories and executes them as the Oracle or System user, which allows attackers to execute arbitrary code by uploading a malicious .fmx file and referencing it using an absolute pathname argument in the (1) form or (2) module parameters to f90servlet.

CVSS2: 7.2
EPSS: Низкий
github логотип

GHSA-h3q5-7899-7pxx

почти 4 года назад

Oracle Forms 4.5 through 10g starts form executables from arbitrary directories and executes them as the Oracle or System user, which allows attackers to execute arbitrary code by uploading a malicious .fmx file and referencing it using an absolute pathname argument in the (1) form or (2) module parameters to f90servlet.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2005-2372

Oracle Forms 4.5 through 10g starts form executables from arbitrary directories and executes them as the Oracle or System user, which allows attackers to execute arbitrary code by uploading a malicious .fmx file and referencing it using an absolute pathname argument in the (1) form or (2) module parameters to f90servlet.

CVSS2: 7.2
3%
Низкий
больше 20 лет назад
github логотип
GHSA-h3q5-7899-7pxx

Oracle Forms 4.5 through 10g starts form executables from arbitrary directories and executes them as the Oracle or System user, which allows attackers to execute arbitrary code by uploading a malicious .fmx file and referencing it using an absolute pathname argument in the (1) form or (2) module parameters to f90servlet.

3%
Низкий
почти 4 года назад

Уязвимостей на страницу