Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Workaround for unpatched Oracle PLSQL Gateway flaw Jan 25 2006 06:25PM
David Litchfield (davidl ngssoftware com)
There's a critical flaw in the Oracle PLSQL Gateway, a component of iAS, OAS
and the Oracle HTTP Server, that allows attackers to bypass the
PLSQLExclusion list and gain access to "excluded" packages and procedures.
This can be exploited by an attacker to gain full DBA control of the backend
dat...

[ more ]  





 

Privacy Statement
Copyright 2008, SecurityFocus