Oracle Application Server PL/SQL Module Format String Vulnerability
BID:4844
Info
Oracle Application Server PL/SQL Module Format String Vulnerability
| Bugtraq ID: | 4844 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 27 2002 12:00AM |
| Updated: | May 27 2002 12:00AM |
| Credit: | Vulnerability discovery credited to Next Generation Security Software. |
| Vulnerable: |
Oracle Application Server 4.0.8 .2 Oracle Application Server 4.0.8 |
| Not Vulnerable: | |
Discussion
Oracle Application Server PL/SQL Module Format String Vulnerability
Application Server is a commercially available web application development package distributed by Oracle.
A format string vulnerability has been discovered in the Application Server. This problem may allow an attacker to write data to arbitrary addresses in memory, and potentially execute arbitrary code.
Application Server is a commercially available web application development package distributed by Oracle.
A format string vulnerability has been discovered in the Application Server. This problem may allow an attacker to write data to arbitrary addresses in memory, and potentially execute arbitrary code.
Exploit / POC
Oracle Application Server PL/SQL Module Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.