CVE-2004-1364
published 2004-08-04CVE-2004-1364: Directory traversal vulnerability in extproc in Oracle 9i and 10g allows remote attackers to access arbitrary libraries outside of the $ORACLE_HOME\bin…
PriorityP349high8.5CVSS 2.0
AVNACMAuSCCICAC
EXPLOIT
EPSS
13.78%
96.1th percentile
Directory traversal vulnerability in extproc in Oracle 9i and 10g allows remote attackers to access arbitrary libraries outside of the $ORACLE_HOME\bin directory.
Affected
86 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | application_server | — | — |
| oracle | application_server | — | — |
| oracle | application_server | — | — |
| oracle | application_server | — | — |
| oracle | application_server | — | — |
| oracle | application_server | — | — |
| oracle | application_server | — | — |
| oracle | application_server | — | — |
| oracle | application_server | — | — |
| oracle | application_server | — | — |
| oracle | application_server | — | — |
| oracle | collaboration_suite | — | — |
| oracle | e-business_suite | — | — |
| oracle | e-business_suite | — | — |
| oracle | e-business_suite | — | — |
| oracle | e-business_suite | — | — |
| oracle | e-business_suite | — | — |
| oracle | e-business_suite | — | — |
| oracle | e-business_suite | — | — |
| oracle | e-business_suite | — | — |
| oracle | e-business_suite | — | — |
| oracle | enterprise_manager | — | — |
| oracle | enterprise_manager | — | — |
| oracle | enterprise_manager_database_control | — | — |
| oracle | enterprise_manager_grid_control | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
Oracle 9i/10g - 'extproc' Local/Remote Command Execution
exploitdb·2006-12-19·CVSS 8.5
CVE-2004-1364 [HIGH] Oracle 9i/10g - 'extproc' Local/Remote Command Execution
Oracle 9i/10g - 'extproc' Local/Remote Command Execution
---
--
-- $Id: raptor_oraextproc.sql,v 1.1 2006/12/19 14:21:00 raptor Exp $
--
-- raptor_oraextproc.sql - command exec via oracle extproc
-- Copyright (c) 2006 Marco Ivaldi
--
-- Directory traversal vulnerability in extproc in Oracle 9i and 10g
-- allows remote attackers to access arbitrary libraries outside of the
-- $ORACLE_HOME\bin directory (CVE-2004-1364).
--
-- This PL/SQL code exploits the Oracle extproc directory traversal bug
-- to remotely execute arbitrary OS commands with the privileges of the DBMS
-- user (the CREATE [ANY] LIBRARY privilege is needed).
--
-- See also:
-- http://www.0xdeadbeef.info/exploits/raptor_oraexec.sql
-- http://www.0xdeadbeef.info/exploits/raptor_orafile.sql
--
-- Vulnerable platforms:
-- Oracle
Exploit-DB
Oracle 9i - Multiple Vulnerabilities
exploitdb·2004-08-04·CVSS 8.5
CVE-2004-1364 [HIGH] Oracle 9i - Multiple Vulnerabilities
Oracle 9i - Multiple Vulnerabilities
---
source: https://www.securityfocus.com/bid/10871/info
Reportedly, multiple unspecified Oracle products contain multiple unspecified vulnerabilities.
The reported vulnerabilities include SQL-injection issues, buffer-overflow issues, and others.
There have also been reports that issues covered in this BID and resolved in the referenced Oracle patch include trigger-abuse issues, character-set-conversion bugs, and denial-of-service vulnerabilities. More information is pending.
Note that a number of unsupported versions of affected products may also potentially be vulnerable.
--
-- $Id: raptor_oraextproc.sql,v 1.1 2006/12/19 14:21:00 raptor Exp $
--
-- raptor_oraextproc.sql - command exec via oracle extproc
-- Copyright (c) 2006 Marco Ivaldi
--
--
No writeups or analysis indexed.
http://marc.info/?l=bugtraq&m=110382406002365&w=2http://sunsolve.sun.com/search/document.do?assetkey=1-26-101782-1http://www.0xdeadbeef.info/exploits/raptor_oraextproc.sqlhttp://www.kb.cert.org/vuls/id/316206http://www.ngssoftware.com/advisories/oracle23122004B.txthttp://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdfhttp://www.securityfocus.com/archive/1/454861/100/0/threadedhttp://www.securityfocus.com/bid/10871http://www.us-cert.gov/cas/techalerts/TA04-245A.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/18658http://marc.info/?l=bugtraq&m=110382406002365&w=2http://sunsolve.sun.com/search/document.do?assetkey=1-26-101782-1http://www.0xdeadbeef.info/exploits/raptor_oraextproc.sqlhttp://www.kb.cert.org/vuls/id/316206http://www.ngssoftware.com/advisories/oracle23122004B.txthttp://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdfhttp://www.securityfocus.com/archive/1/454861/100/0/threadedhttp://www.securityfocus.com/bid/10871http://www.us-cert.gov/cas/techalerts/TA04-245A.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/18658
2004-08-04
Published