7.2

CVE-2005-2372

Exploit

Oracle Forms 4.5 through 10g starts form executables from arbitrary directories and executes them as the Oracle or System user, which allows attackers to execute arbitrary code by uploading a malicious .fmx file and referencing it using an absolute pathname argument in the (1) form or (2) module parameters to f90servlet.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OracleForms Version3.0
OracleForms Version4.5
OracleForms Version5.0
OracleForms Version6.0
OracleForms Version6i
OracleForms Version9i
OracleForms Version10g
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.59% 0.842
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C