BugTraq
Oracle exploit for CTXSYS.DRVXTABC.CREATE_TABLES and others Nov 28 2009 07:36PM
Andrea Purificato (a purificato uni it) (1 replies)
Re: [rejected] Oracle exploit for CTXSYS.DRVXTABC.CREATE_TABLES and others Dec 02 2009 10:21AM
Andrea Purificato (a purificato uni it)
I wrote:
>CTXSYS.DRVXTABC.CREATE_TABLES injection on Oracle DB 9i/10g (CVE-2009-1991)

Hi all,

I really apologize for the mistake. The released code about this flaw
seems not working because of the "authid current_user" clause used
during the creation of the DRVXTABC package.
There were some contributory causes that drive me into the wrong way.

As previously reported by Alexandr Polyakov, the injection still works
but impacts only confidentiality and integrity.

Regards,
--
Andrea Purificato
http://rawlab.mindcreations.com

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus