Vulnerabilities > CVE-2003-0727 - Unspecified vulnerability in Oracle Database Server
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
PARTIAL Summary
Multiple buffer overflows in the XML Database (XDB) functionality for Oracle 9i Database Release 2 allow local users to cause a denial of service or hijack user sessions.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description Oracle 9i XDB HTTP PASS Overflow (win32). CVE-2003-0727. Remote exploit for win32 platform id EDB-ID:16809 last seen 2016-02-02 modified 2010-09-20 published 2010-09-20 reporter metasploit source https://www.exploit-db.com/download/16809/ title Oracle 9i XDB HTTP PASS Overflow Win32 description Oracle 9i XDB 9.2.0.1 - HTTP PASS Buffer Overflow. CVE-2003-0727. Remote exploit for Windows platform file exploits/windows/remote/42780.py id EDB-ID:42780 last seen 2017-09-26 modified 2017-09-25 platform windows port published 2017-09-25 reporter Exploit-DB source https://www.exploit-db.com/download/42780/ title Oracle 9i XDB 9.2.0.1 - HTTP PASS Buffer Overflow type remote description Oracle XDB FTP Service UNLOCK Buffer Overflow Exploit. CVE-2003-0727. Remote exploit for windows platform id EDB-ID:80 last seen 2016-01-31 modified 2003-08-13 published 2003-08-13 reporter David Litchfield source https://www.exploit-db.com/download/80/ title Oracle XDB FTP Service - UNLOCK Buffer Overflow Exploit description Oracle 9.2.0.1 Universal XDB HTTP Pass Overflow Exploit. CVE-2003-0727. Remote exploit for windows platform id EDB-ID:1365 last seen 2016-01-31 modified 2005-12-08 published 2005-12-08 reporter y0 source https://www.exploit-db.com/download/1365/ title Oracle 9.2.0.1 - Universal XDB HTTP Pass Overflow Exploit description Oracle 9i XDB FTP PASS Overflow (win32). CVE-2003-0727. Remote exploit for win32 platform id EDB-ID:16731 last seen 2016-02-02 modified 2010-04-30 published 2010-04-30 reporter metasploit source https://www.exploit-db.com/download/16731/ title Oracle 9i XDB FTP PASS Overflow Win32 description Oracle 9i XDB FTP UNLOCK Overflow (win32). CVE-2003-0727. Remote exploit for windows platform id EDB-ID:16714 last seen 2016-02-02 modified 2010-10-05 published 2010-10-05 reporter metasploit source https://www.exploit-db.com/download/16714/ title Oracle 9i XDB FTP UNLOCK Overflow Win32
Metasploit
description This module exploits a stack buffer overflow in the authorization code of the Oracle 9i HTTP XDB service. David Litchfield, has illustrated multiple vulnerabilities in the Oracle 9i XML Database (XDB), during a seminar on "Variations in exploit methods between Linux and Windows" presented at the Blackhat conference. id MSF:EXPLOIT/WINDOWS/HTTP/ORACLE9I_XDB_PASS last seen 2020-01-15 modified 2017-07-24 published 2006-10-26 references reporter Rapid7 source https://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/windows/http/oracle9i_xdb_pass.rb title Oracle 9i XDB HTTP PASS Overflow (win32) description By passing an overly long string to the PASS command, a stack based buffer overflow occurs. David Litchfield, has illustrated multiple vulnerabilities in the Oracle 9i XML Database (XDB), during a seminar on "Variations in exploit methods between Linux and Windows" presented at the Blackhat conference. id MSF:EXPLOIT/WINDOWS/FTP/ORACLE9I_XDB_FTP_PASS last seen 2020-05-23 modified 2017-07-24 published 2005-11-25 references reporter Rapid7 source https://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/windows/ftp/oracle9i_xdb_ftp_pass.rb title Oracle 9i XDB FTP PASS Overflow (win32) description By passing an overly long token to the UNLOCK command, a stack based buffer overflow occurs. David Litchfield, has illustrated multiple vulnerabilities in the Oracle 9i XML Database (XDB), during a seminar on "Variations in exploit methods between Linux and Windows" presented at the Blackhat conference. Oracle9i includes a number of default accounts, including dbsnmp:dbsmp, scott:tiger, system:manager, and sys:change_on_install. id MSF:EXPLOIT/WINDOWS/FTP/ORACLE9I_XDB_FTP_UNLOCK last seen 2020-05-23 modified 2018-08-20 published 2006-01-08 references reporter Rapid7 source https://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/windows/ftp/oracle9i_xdb_ftp_unlock.rb title Oracle 9i XDB FTP UNLOCK Overflow (win32)
Packetstorm
data source https://packetstormsecurity.com/files/download/144108/oraclexdbftp-overflow.txt id PACKETSTORM:144108 last seen 2017-09-14 published 2017-08-12 reporter David Litchfield source https://packetstormsecurity.com/files/144108/Oracle-XDB-FTP-Service-UNLOCK-Buffer-Overflow.html title Oracle XDB FTP Service UNLOCK Buffer Overflow data source https://packetstormsecurity.com/files/download/82958/oracle9i_xdb_ftp_unlock.rb.txt id PACKETSTORM:82958 last seen 2016-12-05 published 2009-11-26 reporter David Litchfield source https://packetstormsecurity.com/files/82958/Oracle-9i-XDB-FTP-UNLOCK-Overflow-win32.html title Oracle 9i XDB FTP UNLOCK Overflow (win32) data source https://packetstormsecurity.com/files/download/144341/oracle9ixdb-overflow.txt id PACKETSTORM:144341 last seen 2017-09-26 published 2017-09-26 reporter Charles Dardaman source https://packetstormsecurity.com/files/144341/Oracle-9i-XDB-9.2.01-HTTP-PASS-Buffer-Overflow.html title Oracle 9i XDB 9.2.01 HTTP PASS Buffer Overflow data source https://packetstormsecurity.com/files/download/83144/oracle9i_xdb_ftp_pass.rb.txt id PACKETSTORM:83144 last seen 2016-12-05 published 2009-11-26 reporter MC source https://packetstormsecurity.com/files/83144/Oracle-9i-XDB-FTP-PASS-Overflow-win32.html title Oracle 9i XDB FTP PASS Overflow (win32) data source https://packetstormsecurity.com/files/download/135572/oracle9i_ftp_pass.py.txt id PACKETSTORM:135572 last seen 2016-12-05 published 2016-02-03 reporter MC source https://packetstormsecurity.com/files/135572/Oracle-9i-XDB-FTP-Pass-Overflow.html title Oracle 9i XDB FTP Pass Overflow data source https://packetstormsecurity.com/files/download/82937/oracle9i_xdb_pass.rb.txt id PACKETSTORM:82937 last seen 2016-12-05 published 2009-10-30 reporter MC source https://packetstormsecurity.com/files/82937/Oracle-9i-XDB-HTTP-PASS-Overflow-win32.html title Oracle 9i XDB HTTP PASS Overflow (win32)
Saint
bid 8375 description Oracle 9i Release 2 XDB FTP Pass Overflow id database_oracle_xdb osvdb 2449 title oracle_xdb_ftp_pass_overflow type remote bid 8375 description Oracle 9i Release 2 XDB HTTP Pass Overflow id database_oracle_xdb osvdb 2449 title oracle_xdb_http_pass_overflow type remote