Oracle Forms是oracle的一个组件。 Oracle Forms 4.5至10g存在执行任意代码漏洞。forms会从任意目录中的可执行文件启动,并以Oracle或System用户身份来执行,攻击者可以通过上传恶意.fmx文件并使用(1)表单中的绝对路径名参数或(2)f90servlet的模块参数执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2005-2373 | SlimFTPd long directory name 缓冲区溢出漏洞 | |
| CVE-2005-2383 | PHPNews Auth.PHP SQL注入漏洞 | |
| CVE-2005-2382 | Oray PeanutHull 本地权限提升漏洞 | |
| CVE-2005-2381 | PHP Surveyor 信息泄露漏洞 | |
| CVE-2005-2380 | PHP Surveyor 跨站脚本漏洞 | |
| CVE-2005-2379 | Oracle Reports 跨站脚本漏洞 | |
| CVE-2005-2378 | Oracle Reports Server 信息泄露漏洞 | |
| CVE-2005-2377 | nss_ldap SIGPIPE 拒绝服务漏洞 | |
| CVE-2005-2376 | ToCA Race Driver 缓冲区溢出漏洞 | |
| CVE-2005-2375 | ToCA Race Driver 格式化字符串漏洞 | |
| CVE-2005-2374 | Belkin 54g wireless routers 管理员密码漏洞 | |
| CVE-2005-1691 | SAP Internet Graphics Server ".." 目录遍历漏洞 | |
| CVE-2005-2371 | Oracle Reports Server DESName 文件覆盖漏洞 | |
| CVE-2005-2370 | ekg libgadu 内存队列错误漏洞 | |
| CVE-2005-2369 | ekg libgadu 有符号类型整数错误溢出漏洞 | |
| CVE-2005-2368 | Vim modelines 任意命令执行漏洞 | |
| CVE-2005-2276 | Novell GroupWise WebAccess 跨站脚本漏洞 | |
| CVE-2005-2218 | FreeBSD devfs 规则绕过漏洞 | |
| CVE-2005-1920 | KDE Kate/Kwrite 信息泄露漏洞 | |
| CVE-2005-1852 | ekg libgadu 多个整数溢出漏洞 |
Showing top 20 of 22 CVEs. View all on vendor page → →
No comments yet