exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 51 - 67 of 67 RSS Feed

Files from Esteban Martinez Fayo

Email addresssecemf at gmail.com
First Active2004-09-09
Last Active2024-08-31
oracle-dbms.txt
Posted Oct 29, 2007
Authored by Esteban Martinez Fayo | Site appsecinc.com

Team SHATTER Security Alert - Oracle Database Server provides the SYS.DBMS_AQADM_SYS package that is used internally by the SYS.DBMS_AQADM package to provide procedures to manage Oracle Streams Advanced Queuing (AQ) configuration and administration information. This package contains the procedure DBLINK_INFO which is vulnerable to buffer overflow attacks. Affected versions include Oracle Database Server versions 9iR1, 9iR2 (9.2.0.7 and previous patchsets) and 10gR1.

tags | advisory, overflow
SHA-256 | 58d76e3a0aef0c6352b4c4758f736521b656d25dc7b79ead00dce2d59a6de04b
oracle-mdsys.txt
Posted Oct 29, 2007
Authored by Esteban Martinez Fayo | Site appsecinc.com

Team SHATTER Security Alert - Oracle Database Server provides the MDSYS.SDO_CS package that contains subprograms for working with coordinate systems. This package contains the function TRANSFORM which is vulnerable to buffer overflow attacks. Affected versions include Oracle Database Server versions 8iR3, 9iR1, 9iR2 (9.2.0.6 and previous patchsets) and 10gR1 (10.1.0.4 and previous patchsets).

tags | advisory, overflow
SHA-256 | c1a8396a98fadf1347f49ba35e4dac43085a4c2e84bd788266f80b864f34c281
shatter-mdsysmd.txt
Posted Jul 19, 2007
Authored by Esteban Martinez Fayo | Site appsecinc.com

Team SHATTER Security Alert - The Oracle Database Server provides the MDSYS.MD package that is used in the Oracle Spatial component. These packages contain many public procedures that are vulnerable to buffer overflow and denial of service attacks.

tags | advisory, denial of service, overflow
advisories | CVE-2007-0272
SHA-256 | b7f6615f0debbfe75e060b13acd0cdd0900a209be592fb4d5cb17d1cc4a86b48
shatter-dbmsdrs.txt
Posted Jul 19, 2007
Authored by Esteban Martinez Fayo | Site appsecinc.com

Team SHATTER Security Alert - Oracle Database Server provides the DBMS_DRS package that includes procedures used in Oracle Data Guard. This package contains the function GET_PROPERTY which is vulnerable to buffer overflow attacks.

tags | advisory, overflow
advisories | CVE-2007-0270
SHA-256 | f258346bd6b03df6189ea2005f49b6ab5132d3b45e0b7b60c5b3544cd5a0ca45
ods-overflow.txt
Posted Apr 19, 2007
Authored by Esteban Martinez Fayo | Site appsecinc.com

Oracle Database Server version 8i, 9i, and 10gR1 suffer from buffer overflow vulnerabilities in DBMS_SNAP_INTERNAL.

tags | advisory, overflow, vulnerability
SHA-256 | e2719905e19ea0ea42e881bdd6793b1527d1bdebb9522c082597bf21d1f8db5e
OraGENERATESCHEMAExploits.txt
Posted Jan 29, 2006
Authored by Esteban Martinez Fayo | Site argeniss.com

Oracle 10g Release 1 exploit for the GENERATESCHEMA buffer overflow with shellcode that creates a file named Unbreakable.txt.

tags | exploit, overflow, shellcode
SHA-256 | 8dcd96b32a3ae1a3fe4c1eab28829ac25e5c1eadd36797cb4a889d49c78de7f6
ARGENISS-ADV-010601.txt
Posted Jan 29, 2006
Authored by Esteban Martinez Fayo | Site argeniss.com

Argeniss Security Advisory - Oracle Database Server provides the DBMS_XMLSCHEMA and DBMS_XMLSCHEMA_INT Packages that include procedures to register and delete XML schemas. These packages contain the public procedures GENERATESCHEMA and GENERATESCHEMAS that are vulnerable to buffer overflow attacks.

tags | advisory, overflow
SHA-256 | 367ed9eab6261d53ec2bfcaf1f65901f75fa8a8fa1f0d9139fb4c8389da1b9d7
WEBSP05-V0098.txt
Posted Jun 20, 2005
Authored by Esteban Martinez Fayo | Site appsecinc.com

A remote buffer overflow exists in the WebSphere application server administrative console.

tags | advisory, remote, overflow
SHA-256 | e74e8ec2a3d866f38cbe94ade110b68eba3f1bf9f6b2b3b2c968770fe1798347
AppSecInc.create.txt
Posted May 30, 2005
Authored by Esteban Martinez Fayo | Site appsecinc.com

A SQL injection vulnerability exists in the CREATE_SCN_CHANGE_SET procedure for Oracle database server version 10g.

tags | advisory, sql injection
SHA-256 | a5212af4697367cfaddf9c5d2eecf257e160ca8ab7b17e47a8d5fbd82766578d
AppSecInc.alter.txt
Posted May 30, 2005
Authored by Esteban Martinez Fayo | Site appsecinc.com

A SQL injection vulnerability exists in the ALTER_MANUALLOG_CHANGE_SOURCEDBMS_METADATA procedure for Oracle database server version 10g.

tags | advisory, sql injection
SHA-256 | 6fe16250b05705d0c21788a7123ad48bf9b396fddbabb93bae3b81090b8ca7eb
AppSecInc.oracleDBMS.txt
Posted May 30, 2005
Authored by Esteban Martinez Fayo | Site appsecinc.com

Multiple SQL injection vulnerabilities exist in the DBMS_METADATA package for Oracle database server versions 9i and 10g.

tags | advisory, vulnerability, sql injection
SHA-256 | 9c197b54da59422b26a68e8b4cc788a15635ca92f877520ad3c5ec7c525b0aa3
AppSecInc.oracleSQL.txt
Posted May 29, 2005
Authored by Esteban Martinez Fayo | Site appsecinc.com

Oracle Database Server version 10g has a flaw that allows any low privileged database user to execute functions with DBA privileges.

tags | advisory
SHA-256 | bd2ea7fcfad3776a3eb567cbc888e2578d0c447e690779f98950f1bccc8ab1db
AppSecInc.oracle.txt
Posted May 29, 2005
Authored by Esteban Martinez Fayo | Site appsecinc.com

Oracle Database Server versions 9i and 10g suffer from denial of service vulnerabilities in their interMedia system.

tags | advisory, denial of service, vulnerability
SHA-256 | 6fa9a30526c515903a896294e0fe106983bd5cf8a9bcc4ecab61acd3f4f6e5fc
plsql_multiplestatement_injection.txt
Posted Apr 19, 2005
Authored by Esteban Martinez Fayo

Specialized exploit for cases where SQL injection is possible against a Oracle PL/SQL setup.

tags | exploit, sql injection
SHA-256 | d157fd2dfa2d66e860e087333a9d56513595d3653e44b2708d42626d1eb78d34
oracle_sdo_code_size.c
Posted Apr 19, 2005
Authored by Esteban Martinez Fayo

Exploit for buffer overflow vulnerability in procedure MDSYS.MD2.SDO_CODE_SIZE within Oracle Database Server version 10.1.0.2 under Windows 2000 SP4.

tags | exploit, overflow
systems | windows
SHA-256 | a0f3cca0424aca2f2583ed61ffa387e3f18c17050746fbcb5ef2f5de1e81146f
AdvancedSQLInjectionInOracleDatabases.zip
Posted Feb 6, 2005
Authored by Esteban Martinez Fayo | Site security-papers.globint.com.ar

This presentation explores new methods in exploiting SQL injection vulnerabilities inherent in Oracle Database. It contains a presentation with 37 slides and various exploits that demonstrate examples of flaws.

tags | paper, vulnerability, sql injection
SHA-256 | 40233cb1502c958361ff1184ec472b9a2194b8341030a7d5db67ad47bf88d951
AppSecInc.Oracle.txt
Posted Sep 9, 2004
Authored by Cesar Cerrudo, Esteban Martinez Fayo | Site appsecinc.com

AppSecInc Advisory - Multiple buffer overflow and denial of service (DoS) vulnerabilities exist in the Oracle Database Server which allow database users to take complete control over the database and optionally cause denial of service. Forty-four buffer overflows have been found. Exploitation of these vulnerabilities will allow an attacker to completely compromise the OS and the database if Oracle is running on Windows platform, because Oracle must run under the local System account or under an administrative account. If Oracle is running on *nix then only the database would be compromised because Oracle runs mostly under oracle user which has restricted permissions.

tags | advisory, denial of service, overflow, local, vulnerability
systems | windows
SHA-256 | 36977a3722720f6c3f2f1e3bbe50f6af68d1a8103afc604a75caff18382bb344
Page 3 of 3
Back123Next

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    0 Files
  • 12
    Nov 12th
    0 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close