CVE-2005-2372

Oracle Forms 4.5 through 10g starts form executables from arbitrary directories and executes them as the Oracle or System user, which allows attackers to execute arbitrary code by uploading a malicious .fmx file and referencing it using an absolute pathname argument in the (1) form or (2) module parameters to f90servlet.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:oracle:forms:3.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:forms:4.5:*:*:*:*:*:*:*
cpe:2.3:a:oracle:forms:5.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:forms:6.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:forms:6i:*:*:*:*:*:*:*
cpe:2.3:a:oracle:forms:9i:*:*:*:*:*:*:*
cpe:2.3:a:oracle:forms:10g:*:*:*:*:*:*:*

History

20 Nov 2024, 23:59

Type Values Removed Values Added
References () http://marc.info/?l=bugtraq&m=112180805413784&w=2 - () http://marc.info/?l=bugtraq&m=112180805413784&w=2 -
References () http://www.red-database-security.com/advisory/oracle_forms_run_any_os_command.html - Exploit, Vendor Advisory () http://www.red-database-security.com/advisory/oracle_forms_run_any_os_command.html - Exploit, Vendor Advisory

Information

Published : 2005-07-26 04:00

Updated : 2025-04-03 01:03


NVD link : CVE-2005-2372

Mitre link : CVE-2005-2372

CVE.ORG link : CVE-2005-2372


JSON object : View

Products Affected

oracle

  • forms