Vulnerabilities > CVE-2009-1978 - Arbitrary Command Execution vulnerability in Oracle Secure Backup 10.2.0.3

047910
CVSS 9.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
oracle
critical
metasploit

Summary

Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the July 2009 Oracle CPU. Oracle has not commented on claims from an independent researcher that this vulnerability allows remote authenticated users to execute arbitrary code with SYSTEM privileges via vectors involving property_box.php.

Vulnerable Configurations

Part Description Count
Application
Oracle
1

D2sec

nameOracle Secure Backup 10.3.0.1 RCE
urlhttp://www.d2sec.com/exploits/oracle_secure_backup_10.3.0.1_rce.html

Metasploit

descriptionThis module exploits an authentication bypass vulnerability in login.php in order to execute arbitrary code via a command injection vulnerability in property_box.php. This module was tested against Oracle Secure Backup version 10.3.0.1.0 (Win32).
idMSF:AUXILIARY/ADMIN/ORACLE/OSB_EXECQR2
last seen2019-12-13
modified2017-07-24
published2009-09-16
references
reporterRapid7
sourcehttps://github.com/rapid7/metasploit-framework/blob/master//modules/auxiliary/admin/oracle/osb_execqr2.rb
titleOracle Secure Backup Authentication Bypass/Command Injection Vulnerability

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/81262/osbs-bypass.txt
idPACKETSTORM:81262
last seen2016-12-05
published2009-09-15
reporterLuca Carettoni
sourcehttps://packetstormsecurity.com/files/81262/Oracle-Secure-Backup-Server-Bypass-Command-Injection.html
titleOracle Secure Backup Server Bypass / Command Injection

Saint

bid35678
descriptionOracle Secure Backup property_box.php type parameter command execution
iddatabase_oracle_backupver
osvdb55904
titleoracle_secure_backup_property_box_type
typeremote

Seebug

bulletinFamilyexploit
descriptionNo description provided by source.
idSSV:12329
last seen2017-11-19
modified2009-09-16
published2009-09-16
reporterRoot
sourcehttps://www.seebug.org/vuldb/ssvid-12329
titleOracle Secure Backup Server 10.3.0.1.0 Auth Bypass/RCI Exploit