peter bassill · operator
$ cve CVE-2005-0701 JSON

CVE-2005-0701 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 18.1% (pctl 97)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in Oracle Database Server 8i and 9i allows remote attackers to read or rename arbitrary files via "\\.\\.." (modified dot dot backslash) sequences to UTL_FILE functions such as (1) UTL_FILE.FOPEN or (2) UTL_FILE.frename.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS18.15% — more likely to be exploited than 97% of all CVEs
On CISA KEVno
Public exploityes
Published2005-03-07
Last modified2026-06-16

Affected (1)

VendorProduct
oracledatabase server

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD