← Back

CVE-2005-2372

nvd nist
Published: Jul 26, 2005Modified: Apr 16, 2026

JSON object

Loading...
7.2
Vector
AV:L/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 3.9 / Impact: 10.0
Source: NVD

Description

Oracle Forms 4.5 through 10g starts form executables from arbitrary directories and executes them as the Oracle or System user, which allows attackers to execute arbitrary code by uploading a malicious .fmx file and referencing it using an absolute pathname argument in the (1) form or (2) module parameters to f90servlet.

Affected (7)

Products: Oracle: Forms
1 product
Forms
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 10g
Version 3.0
Version 4.5
Version 5.0
Version 6.0
Version 6i
Version 9i

References (4)

Timeline

No history available yet.