Security Portal

Intrusion Prevention Service

 
Signature Version: 4.788

 



EXPLOIT Oracle Secure Backup Administration objectname Variable Command Injection (CVE-2010-0906)
 
Threat Level: High
Release Date: 2010/10/25
 
Category: Access Control
Signature ID: 1054265
Included In: Full
Affected OS: Windows
 
Description: A command execution vulnerability exists in Oracle Secure Backup server. The vulnerability is due to an input validation error when property_box.php script handles the $objectname Variable.
 
Impact: Remote code execution
Recommendation: Update vendor's patch.
 
False Positive: None
False Negative: None
 
Additional Information (Links open in new window):
Reference(s): CVE-2010-0906; BID:41597; SA40595; ZDI-10-122
 

Search the Threat Database
Enter Rule ID or Name