CVE-2005-1382

Oracle Webcache 9i - Path Traversal

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2005-1382. PoCs published by Alexander Kornbrust.

AI-analyzed exploit summary The exploit describes an arbitrary file corruption vulnerability in Oracle Application Server 9i Webcache due to improper sanitization of a parameter value. An attacker can construct a URI to append garbage data to any target file, potentially leading to denial of service or other unintended consequences.

Description

The webcacheadmin module in Oracle Webcache 9i allows remote attackers to corrupt arbitrary files via a full pathname in the cache_dump_file parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Alexander Kornbrust · textremotemultiple
https://www.exploit-db.com/exploits/25561

The exploit describes an arbitrary file corruption vulnerability in Oracle Application Server 9i Webcache due to improper sanitization of a parameter value. An attacker can construct a URI to append garbage data to any target file, potentially leading to denial of service or other unintended consequences.

Classification
Writeup 90%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: Oracle Application Server 9i Webcache
Auth required
Prerequisites: Access to a user with sufficient privileges to trigger the vulnerability
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (6)

Core 6
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=111472615519295&w=2
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/15143
Vendor Advisory vdb-entry x_refsource_osvdb
http://www.osvdb.org/15909
Exploit, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/13420
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/20310

Scores

EPSS 0.0701
EPSS Percentile 93.3%

Details

Status published
Products (1)
oracle/application_server_web_cache
Published May 03, 2005
Tracked Since Feb 18, 2026