knowledge is security
Showing 1 - 1 of 1 RSS Feed

Files

Oracle Database SQL Injection In DBMS_CDC_PUBLISH.DROP_CHANGE_SOURCE
Posted Apr 27, 2010
Authored by Esteban Martinez Fayo | Site appsecinc.com

Team SHATTER Security Advisory - Oracle Database provides the DBMS_CDC_PUBLISH PL/SQL package owned by SYS that is part of the Change Data Capture component. This package has a SQL Injection vulnerability in DROP_CHANGE_SOURCE procedure. A malicious user can call the vulnerable procedure of this package with specially crafted parameters and execute SQL statements with the elevated privileges of the SYS user.

tags | advisory, sql injection
advisories | CVE-2010-0870
MD5 | fbc0d87ac1e6e8705513c2db028c634e
Page 1 of 1
Back1Next

Top Authors In Last 30 Days

packet storm

© 2012 Packet Storm. All rights reserved.

close