Vulnerabilities > CVE-2005-4832 - Unspecified vulnerability in Oracle Oracle10G
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
SQL injection vulnerability in the Oracle Database Server 10g allows remote authenticated users to execute arbitrary SQL commands with elevated privileges via the SUBSCRIPTION_NAME parameter in the (1) SYS.DBMS_CDC_SUBSCRIBE and (2) SYS.DBMS_CDC_ISUBSCRIBE packages, a different vector than CVE-2005-1197.
Vulnerable Configurations
Exploit-Db
description Oracle 10g Database SUBSCRIPTION_NAME Remote SQL Injection Vulnerability (1). CVE-2005-4832 . Remote exploits for multiple platform id EDB-ID:25452 last seen 2016-02-03 modified 2007-02-23 published 2007-02-23 reporter bunker source https://www.exploit-db.com/download/25452/ title Oracle 10g Database SUBSCRIPTION_NAME Remote SQL Injection Vulnerability 1 description Oracle 10g Database SUBSCRIPTION_NAME Remote SQL Injection Vulnerability (2). CVE-2005-4832 . Remote exploits for multiple platform id EDB-ID:25453 last seen 2016-02-03 modified 2007-02-26 published 2007-02-26 reporter bunker source https://www.exploit-db.com/download/25453/ title Oracle 10g Database SUBSCRIPTION_NAME Remote SQL Injection Vulnerability 2
Metasploit
description | This module will escalate an Oracle DB user to DBA by exploiting a sql injection bug in the SYS.DBMS_CDC_SUBSCRIBE.ACTIVATE_SUBSCRIPTION package/function. This vulnerability affects to Oracle Database Server 9i up to 9.2.0.5 and 10g up to 10.1.0.4. |
id | MSF:AUXILIARY/SQLI/ORACLE/DBMS_CDC_SUBSCRIBE_ACTIVATE_SUBSCRIPTION |
last seen | 2020-06-01 |
modified | 2017-08-29 |
published | 2011-12-13 |
references | |
reporter | Rapid7 |
source | https://github.com/rapid7/metasploit-framework/blob/master//modules/auxiliary/sqli/oracle/dbms_cdc_subscribe_activate_subscription.rb |
title | Oracle DB SQL Injection via SYS.DBMS_CDC_SUBSCRIBE.ACTIVATE_SUBSCRIPTION |
Nessus
NASL family | Databases |
NASL id | ORACLE_MULTIPLE.NASL |
description | According to its version number, the installation of Oracle on the remote host is reportedly subject to multiple vulnerabilities, some of which don |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 18034 |
published | 2005-04-13 |
reporter | This script is Copyright (C) 2005-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/18034 |
title | Oracle Database 10g Multiple Remote Vulnerabilities |
code |
|
References
- http://www.appsecinc.com/resources/alerts/oracle/2005-02.html
- http://www.appsecinc.com/resources/alerts/oracle/2005-02.html
- http://www.argeniss.com/research/OraDBMS_CDC_SUBSCRIBEExploit.txt
- http://www.argeniss.com/research/OraDBMS_CDC_SUBSCRIBEExploit.txt
- http://www.argeniss.com/research/OraDBMS_CDC_SUBSCRIBEWorkaround.sql
- http://www.argeniss.com/research/OraDBMS_CDC_SUBSCRIBEWorkaround.sql
- http://www.oracle.com/technology/deploy/security/pdf/cpuapr2005.pdf
- http://www.oracle.com/technology/deploy/security/pdf/cpuapr2005.pdf
- http://www.securityfocus.com/archive/1/396133
- http://www.securityfocus.com/archive/1/396133
- http://www.securityfocus.com/archive/1/404970
- http://www.securityfocus.com/archive/1/404970
- http://www.securityfocus.com/bid/13236
- http://www.securityfocus.com/bid/13236
- https://exchange.xforce.ibmcloud.com/vulnerabilities/20159
- https://exchange.xforce.ibmcloud.com/vulnerabilities/20159