Description
Oracle Forms 4.5 through 10g starts form executables from arbitrary directories and executes them as the Oracle or System user, which allows attackers to execute arbitrary code by uploading a malicious .fmx file and referencing it using an absolute pathname argument in the (1) form or (2) module parameters to f90servlet.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2005-2373 | Oracle Forms 4.5 through 10g starts form executables from arbitrary directories and executes them as the Oracle or System user, which allows attackers to execute arbitrary code by uploading a malicious .fmx file and referencing it using an absolute pathname argument in the (1) form or (2) module parameters to f90servlet. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T22:22:49.050Z
Reserved: 2005-07-26T00:00:00.000Z
Link: CVE-2005-2372
No data.
Status : Modified
Published: 2005-07-26T04:00:00.000
Modified: 2026-04-16T00:27:16.627
Link: CVE-2005-2372
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD