|
Full Disclosure
mailing list archives
Re: [rejected] Oracle exploit for CTXSYS.DRVXTABC.CREATE_TABLES and others
From: "Andrea Purificato" <a.purificato () uni it>
Date: Wed, 02 Dec 2009 12:21:30 +0200
I wrote:
CTXSYS.DRVXTABC.CREATE_TABLES injection on Oracle DB 9i/10g (CVE-2009-1991)
Hi all,
I really apologize for the mistake. The released code about this flaw
seems not working because of the "authid current_user" clause used
during the creation of the DRVXTABC package.
There were some contributory causes that drive me into the wrong way.
As previously reported by Alexandr Polyakov, the injection still works
but impacts only confidentiality and integrity.
Regards,
--
Andrea Purificato
http://rawlab.mindcreations.com
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
By Date
By Thread
Current thread:
- Re: [rejected] Oracle exploit for CTXSYS.DRVXTABC.CREATE_TABLES and others Andrea Purificato (Dec 02)
|