CVE-2008-4006
iDEFENSE Security Advisory 2009-01-13.1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.1.0.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
Vulnerabilidad sin especificar en el componente Oracle Secure Backup en Oracle Secure Backup 10.1.0.3, permite a atacantes remotos comprometer la integridad, confidencialidad y disponibilidad a través de vectores desconocidos.
Remote exploitation of two command injection vulnerabilities in the authentication component of Oracle Corp.'s Secure Backup Administration Server could allow an unauthenticated attacker to execute arbitrary commands in the context of the running server. In both cases, the vulnerabilities exist in PHP scripts that authenticate a user attempting to use the service. The first vulnerability is in "php/login.php". By making a login request with a specially crafted cookie value, an attacker can execute arbitrary code on the server. The second vulnerability is in "php/common.php". This function is called from the "login.php" page. A variable is used to specify a command to be run. An attacker can supply any shell command for this variable and it will be executed in the context of the web server process. Oracle Corp.'s Secure Backup version 10.2.0.2 for Linux, and Secure Backup version 10.2.0.2 for Windows have been confirmed vulnerable. Other versions and other platforms may also be affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-09-09 CVE Reserved
- 2009-01-14 CVE Published
- 2024-08-07 CVE Updated
- 2025-06-05 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/33525 | Third Party Advisory | |
http://www.oracle.com/technetwork/topics/security/cpujan2009-097901.html | X_refsource_confirm |
|
http://www.securityfocus.com/bid/33177 | Vdb Entry | |
http://www.vupen.com/english/advisories/2009/0115 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Oracle Search vendor "Oracle" | Secure Backup Search vendor "Oracle" for product "Secure Backup" | 10.1.0.3 Search vendor "Oracle" for product "Secure Backup" and version "10.1.0.3" | - |
Affected
|