CVE-2010-2370
published 2010-07-13CVE-2010-2370: Unspecified vulnerability in the Oracle Business Process Management component in Oracle Fusion Middleware 5.7 MP3, 6.0 MP5, and 10.3 MP2 allows remote…
PriorityP427medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EXPLOIT
EPSS
3.93%
89.3th percentile
Unspecified vulnerability in the Oracle Business Process Management component in Oracle Fusion Middleware 5.7 MP3, 6.0 MP5, and 10.3 MP2 allows remote attackers to affect integrity, related to BPM.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | fusion_middleware | — | — |
| oracle | fusion_middleware | — | — |
| oracle | fusion_middleware | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
Microsoft RRAS Service - RASMAN Registry Overflow (MS06-025) (Metasploit)
exploitdb·2010-08-25
CVE-2006-2370 Microsoft RRAS Service - RASMAN Registry Overflow (MS06-025) (Metasploit)
Microsoft RRAS Service - RASMAN Registry Overflow (MS06-025) (Metasploit)
---
##
# $Id: ms06_025_rasmans_reg.rb 10150 2010-08-25 20:55:37Z jduck $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 'Microsoft RRAS Service RASMAN Registry Overflow',
'Description' => %q{
This module exploits a registry-based stack buffer overflow in the Windows Routing
and Remote Access Service. Since the service is hosted inside svchost.exe,
a failed exploit attempt can cause other system services to fail as well.
A valid username and password is required to exp
Exploit-DB
Oracle Business Process Management 10.3.2 - Cross-Site Scripting
exploitdb·2010-07-13
CVE-2010-2370 Oracle Business Process Management 10.3.2 - Cross-Site Scripting
Oracle Business Process Management 10.3.2 - Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/41617/info
Oracle Business Process Management is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
This vulnerability affects the following supported versions:
5.7 MP3, 6.0 MP5, 10.3 MP2
http://www.example.com:8585/webconsole/faces/faces/faces/jsf/tips.jsp?context=alert(document.cookie)
http://www.example.com:8585/webconsole/faces/faces/faces/jsf/tips.jsp?context=alert('CorelanTeam'
Exploit-DB
Microsoft RRAS Service - Remote Overflow (MS06-025) (Metasploit)
exploitdb·2010-05-09
CVE-2006-2370 Microsoft RRAS Service - Remote Overflow (MS06-025) (Metasploit)
Microsoft RRAS Service - Remote Overflow (MS06-025) (Metasploit)
---
##
# $Id: ms06_025_rras.rb 9262 2010-05-09 17:45:00Z jduck $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 'Microsoft RRAS Service Overflow',
'Description' => %q{
This module exploits a stack buffer overflow in the Windows Routing and Remote
Access Service. Since the service is hosted inside svchost.exe, a failed
exploit attempt can cause other system services to fail as well. A valid
username and password is required to exploit this flaw on Windows 2000.
When attacking X
No writeups or analysis indexed.
2010-07-13
Published