Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Absolute path traversal vulnerability in Oracle Database Server, when utl_file_dir is set to a wildcard value or "CREATE ANY DIRECTORY to PUBLIC" privileges exist, allows remote authenticated users to read and modify arbitrary files via full filepaths to utl_file functions such as (1) utl_file.put_line and (2) utl_file.get_line, a related issue to CVE-2005-0701. NOTE: this issue is disputed by third parties who state that this is due to an insecure configuration instead of an inherent vulnerability
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Oracle Database Server 绝对路径遍历漏洞
Vulnerability Description
**有争议的** Oracle Database Server中存在绝对路径遍历漏洞。当utl_file_dir被设置成外卡值或"创建任意目录到公开"特权存在时,远程认证用户可以借助对utl_file函数的全文件路径,比如(1)utl_file.put_line和(2)utl_file.get_line,读取和修改任意文件。该漏洞与CVE-2005-0701有关。
CVSS Information
N/A
Vulnerability Type
N/A