Oracle Oracle Reports 6i

CPE Details

Oracle Oracle Reports 6i
6i
2007-08-23
19h16 +00:00
2008-04-01
14h41 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:oracle:reports:6i:*:*:*:*:*:*:*

Informations

Vendor

oracle

Product

reports

Version

6i

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2005-2371 2005-07-26 02h00 +00:00 Directory traversal vulnerability in Oracle Reports 6.0, 6i, 9i, and 10g allows remote attackers to overwrite arbitrary files via (1) "..", (2) Windows drive letter (C:), and (3) absolute path sequences in the desname parameter. NOTE: this issue was probably fixed by REP06 in CPU Jan 2006, in which case it overlaps CVE-2006-0289.
5
CVE-2005-2378 2005-07-26 02h00 +00:00 Directory traversal vulnerability in Oracle Reports allows remote attackers to read arbitrary files via an absolute or relative path to the (1) CUSTOMIZE or (2) desformat parameters to rwservlet. NOTE: vector 2 is probably the same as CVE-2006-0289, and fixed in Jan 2006 CPU.
5