CVE-2005-0701 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 18.1% (pctl 97)
Patch early
A public exploit exists.
Description
Directory traversal vulnerability in Oracle Database Server 8i and 9i allows remote attackers to read or rename arbitrary files via "\\.\\.." (modified dot dot backslash) sequences to UTL_FILE functions such as (1) UTL_FILE.FOPEN or (2) UTL_FILE.frename.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| EPSS | 18.15% — more likely to be exploited than 97% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2005-03-07 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| oracle | database server |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Oracle Database 8i/9i - Multiple Directory Traversal Vulnerabilities | 2005-03-07 |
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-March/032273.html
- http://marc.info/?l=bugtraq&m=111023635928211&w=2
- http://www.argeniss.com/research/ARGENISS-ADV-030501.txt
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-March/032273.html
- http://marc.info/?l=bugtraq&m=111023635928211&w=2
- http://www.argeniss.com/research/ARGENISS-ADV-030501.txt
→ the Explorer · watch your stack · NVD