7.2

CVE-2005-2372

Exploit

Oracle Forms 4.5 through 10g starts form executables from arbitrary directories and executes them as the Oracle or System user, which allows attackers to execute arbitrary code by uploading a malicious .fmx file and referencing it using an absolute pathname argument in the (1) form or (2) module parameters to f90servlet.

Data is provided by the National Vulnerability Database (NVD)
OracleForms Version3.0
OracleForms Version4.5
OracleForms Version5.0
OracleForms Version6.0
OracleForms Version6i
OracleForms Version9i
OracleForms Version10g
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 2.59% 0.842
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C