CVE
- Id
- 11907
- CVE No.
- CVE-2005-0701
- Status
- Candidate
- Description
- Directory traversal vulnerability in Oracle Database Server 8i and 9i allows remote attackers to read or rename arbitrary files via "\.\.." (modified dot dot backslash) sequences to UTL_FILE functions such as (1) UTL_FILE.FOPEN or (2) UTL_FILE.frename.
- Phase
- Assigned (20050309)
- Votes
- None (candidate not yet proposed)
- Comments