RULE(RULE ID:307202)

Rule General Information
Release Date: 2016-01-04
Rule Name: Oracle Application Server Reports Arbitrary System Command Execution Vulnerability -1 (CVE-2005-2371)
Severity:
CVE ID:
Rule Protection Details
Description: Directory traversal vulnerability in Oracle Reports 6.0, 6i, 9i, and 10g allows remote attackers to overwrite arbitrary files via (1) "..", (2) Windows drive letter (C:), and (3) absolute path sequences in the desname parameter.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Other Unix
Reference: SecurityFocusBID:14309
Solutions
No information about possible solutions is published. Please use an alternative product to substitude the affected software.