Secunia Logo
 
CVE Reference: CVE-2005-2378
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2005-2378

Description:
Directory traversal vulnerability in Oracle Reports allows remote attackers to read arbitrary files via an absolute or relative path to the (1) CUSTOMIZE or (2) desformat parameters to rwservlet. NOTE: vector 2 is probably the same as CVE-2006-0289, and fixed in Jan 2006 CPU.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/24321

ST
  1014525
  1014527

SAID
  Secunia Advisory: SA18493
  Secunia Advisory: SA18608

MISC
  http://www.red-database-security.com/advisory/oracle_reports_read_any_xml_file.html
  http://www.red-database-security.com/advisory/oracle_reports_read_any_file.html

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/422256/30/7430/threaded
  http://marc.theaimsgroup.com/?l=bugtraq&m=112181054226520&w=2
  http://marc.theaimsgroup.com/?l=bugtraq&m=112181242916757&w=2


Return to the previous page.