First published: Mon Mar 07 2005(Updated: )
Directory traversal vulnerability in Oracle Database Server 8i and 9i allows remote attackers to read or rename arbitrary files via "\\.\\.." (modified dot dot backslash) sequences to UTL_FILE functions such as (1) UTL_FILE.FOPEN or (2) UTL_FILE.frename.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Database |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0701 is considered a critical vulnerability as it allows remote attackers to access sensitive files on Oracle Database Server.
To fix CVE-2005-0701, apply the latest patches or updates provided by Oracle for Database Server 8i and 9i.
The potential impacts of CVE-2005-0701 include unauthorized access to sensitive files and the risk of data exposure or alteration.
CVE-2005-0701 affects Oracle Database Server versions 8i and 9i.
Yes, CVE-2005-0701 can be exploited remotely using directory traversal techniques.