Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Oracle 10g Database SUBSCRIPTION_NAME Remote SQL Injection Vulnerability

The following proof of concept has been developed. If the preconditions are met, the exploit grants DBA privileges to user "SCOTT":

http://www.argeniss.com/research/OraDBMS_CDC_SUBSCRIBEExploit.txt

The following exploits are available:







 

Privacy Statement
Copyright 2008, SecurityFocus