Directory traversal vulnerability in Oracle Database Server 8i and 9i allows remote attackers to read or rename arbitrary files via "\\.\\.." (modified dot dot backslash) sequences to UTL_FILE functions such as (1) UTL_FILE.FOPEN or (2) UTL_FILE.frename.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2005-03-09T05:00:00

Updated: 2024-08-07T21:21:06.600Z

Reserved: 2005-03-09T00:00:00

Link: CVE-2005-0701

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2005-03-07T05:00:00.000

Modified: 2016-10-18T03:13:52.357

Link: CVE-2005-0701

cve-icon Redhat

No data.