ignore security and it'll go away
Showing 1 - 1 of 1 RSS Feed

Files

iDEFENSE Security Advisory 2009-01-13.2
Posted Jan 14, 2009
Authored by iDefense Labs | Site idefense.com

iDefense Security Advisory 01.13.09 - Remote exploitation of an input validation vulnerability in the authentication component of Oracle Corp.'s Secure Backup Administration Server could allow an unauthenticated attacker to execute arbitrary commands in the context of the running server. The vulnerability is in a function of common.php which is called from the login.php page. The script fails to sanitize the input when verifying the user has permission to use the service. Oracle Corp.'s Secure Backup version 10.1.0.3 for Linux has been confirmed vulnerable. Other versions and other platforms may also be affected.

tags | advisory, remote, arbitrary, php
systems | linux
advisories | CVE-2008-5449
MD5 | e31101c17600181d26a55cd9e6c77855
Page 1 of 1
Back1Next

Top Authors In Last 30 Days

packet storm

© 2012 Packet Storm. All rights reserved.

close