First published: Tue Jul 26 2005(Updated: )
Directory traversal vulnerability in Oracle Reports 6.0, 6i, 9i, and 10g allows remote attackers to overwrite arbitrary files via (1) "..", (2) Windows drive letter (C:), and (3) absolute path sequences in the desname parameter. NOTE: this issue was probably fixed by REP06 in CPU Jan 2006, in which case it overlaps CVE-2006-0289.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Reports | =6.0 | |
Oracle Reports | =9i | |
Oracle Reports | =10g | |
Oracle Reports | =6i |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.