Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Extproc in Oracle 9i and 10g does not require authentication to load a library or execute a function, which allows local users to execute arbitrary commands as the Oracle user.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Oracle extproc本地命令执行漏洞
Vulnerability Description
Oracle Database是一款商业性质大型数据库系统。 Oracle extproc装载库和执行函数时缺少正确验证,本地攻击者可以利用这个漏洞以Oracle用户进程执行任意命令。 当extproc装载库和执行一个函数时没有任何验证,本地用户可以无需验证绕过限制执行任意命令。如果配置得当,在10g中,extproc在*nix下以nobody身份运行。
CVSS Information
N/A
Vulnerability Type
N/A