RULE(RULE ID:709567)

Rule General Information
Release Date: 2015-07-23
Rule Name: WEB-OTHER Oracle Application Server Reports Arbitrary System Command Execution Vulnerability -2 (CVE-2005-2371)
Severity:
CVE ID:
Rule Protection Details
Description: Directory traversal vulnerability in Oracle Reports 6.0, 6i, 9i, and 10g allows remote attackers to overwrite arbitrary files via (1) "..", (2) Windows drive letter (C:), and (3) absolute path sequences in the desname parameter.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Others
Reference: SecurityFocusBID:14309
Solutions
No information about possible solutions is published. Please use an alternative product to substitude the affected software.