Vulnerabilities > CVE-2005-1382 - File Corruption vulnerability in Oracle Application Server 9i Webcache Arbitrary
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
PARTIAL Availability impact
NONE Summary
The webcacheadmin module in Oracle Webcache 9i allows remote attackers to corrupt arbitrary files via a full pathname in the cache_dump_file parameter.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Oracle Application Server 9i Webcache Arbitrary File Corruption Vulnerability. CVE-2005-1382 . Remote exploits for multiple platform |
id | EDB-ID:25561 |
last seen | 2016-02-03 |
modified | 2005-04-28 |
published | 2005-04-28 |
reporter | Alexander Kornbrust |
source | https://www.exploit-db.com/download/25561/ |
title | Oracle Application Server 9i Webcache Arbitrary File Corruption Vulnerability |
Nessus
NASL family | Databases |
NASL id | ORACLE_WEB_CACHE_9I_MULTIPLE_VULNS.NASL |
description | According to its banner, the version of Oracle Application Server 9i Webcache installed on the remote host suffers from several flaws: - Arbitrary File Corruption Vulnerability An attacker may be able to corrupt arbitrary files on the remote host by passing the filenames through the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 18175 |
published | 2005-05-02 |
reporter | This script is Copyright (C) 2005-2018 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/18175 |
title | Oracle Application Server 9i Webcache < 9.0.4.0 Multiple Vulnerabilities |
code |
|
References
- http://marc.info/?l=bugtraq&m=111472615519295&w=2
- http://secunia.com/advisories/15143
- http://www.osvdb.org/15909
- http://www.red-database-security.com/advisory/oracle_webcache_append_file_vulnerabilitiy.html
- http://www.securityfocus.com/bid/13420
- https://exchange.xforce.ibmcloud.com/vulnerabilities/20310