CVE-2008-3979

Oracle Database 10.1.0.5 and 10.2.0.2 - Authenticated SQL Injection via MDSYS.SDO_TOPO_DROP_FTBL Trigger

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2008-3979. PoCs published by sh2kerr, including Metasploit module auxiliary/sqli/oracle/droptable_trigger.

AI-analyzed exploit summary This exploit leverages SQL injection in the MDSYS.SDO_TOPO_DROP_FTBL trigger to escalate privileges from a regular Oracle DB user to MDSYS, then to DBA by creating a malicious trigger in the system schema.

Description

Unspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5 and 10.2.0.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors. NOTE: the previous information was obtained from the January 2009 CPU. Oracle has not commented on reliable researcher claims that this issue is a SQL injection vulnerability that allows remote authenticated users to gain MDSYS privileges via the MDSYS.SDO_TOPO_DROP_FTBL trigger.

Exploits (2)

exploitdb WORKING POC VERIFIED
by sh2kerr · rubylocalmultiple
https://www.exploit-db.com/exploits/8074

This exploit leverages SQL injection in the MDSYS.SDO_TOPO_DROP_FTBL trigger to escalate privileges from a regular Oracle DB user to MDSYS, then to DBA by creating a malicious trigger in the system schema.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Oracle Database (specific version not specified)
Auth required
Prerequisites: Valid Oracle DB user credentials · Access to execute SQL commands
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/sqli/oracle/droptable_trigger.rb

This Metasploit module exploits a SQL injection vulnerability in Oracle DB's MDSYS.SDO_TOPO_DROP_FTBL trigger to escalate privileges from a regular user to MDSYS, then to DBA by creating a malicious trigger in the system schema.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Oracle Database (version not specified, but CVE-2008-3979 affects multiple versions)
Auth required
Prerequisites: Valid Oracle DB credentials with basic privileges · Access to execute SQL queries
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/51354
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33525
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1021561
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/0115
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/33177
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/8074
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/500061/100/0/threaded

Scores

EPSS 0.3243
EPSS Percentile 98.1%

Details

Status published
Products (2)
oracle/database_10g 10.1.0.5
oracle/database_10g 10.2.0.2
Published Jan 14, 2009
Tracked Since Feb 18, 2026