32291Third-party advisory
http://secunia.com/advisories/32291 CVE-2008-3982
Oracle DB SQL Injection via SYS.LT.COMPRESSWORKSPACE
Record summary
CVE-2008-3982 has a selected CVSS score of 5.5; EIP currently links 1 catalogued exploit.
Description
Unspecified vulnerability in the Workspace Manager component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.3, and 11.1.0.6 allows remote authenticated users to affect confidentiality and integrity, related to SYS.LT and WMSYS.LT, a different vulnerability than CVE-2008-3983 and CVE-2008-3984.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
MetasploitOracle DB SQL Injection via SYS.LT.COMPRESSWORKSPACEMetasploit auxiliary PoCby CG <cg@carnal0wnage.com>Not analyzed1 file
References
6oracle.comConfirmation
http://www.oracle.com/technetwork/topics/security/cpuoct2008-100299.html 1021050vdb entry
http://www.securitytracker.com/id?1021050 ADV-2008-2825vdb entry
http://www.vupen.com/english/advisories/2008/2825 oracle-database-workspace-priv-escalation1(45885)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/45885 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-3982