Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-3995.
PoCs published by MC, including Metasploit module auxiliary/sqli/oracle/dbms_cdc_publish.
AI-analyzed exploit summary This Metasploit module exploits a SQL injection vulnerability in Oracle Database Server's SYS.DBMS_CDC_PUBLISH.ALTER_AUTOLOG_CHANGE_SOURCE procedure. It creates a malicious function to execute arbitrary SQL commands, leveraging the vulnerability to grant elevated privileges.
Description
Unspecified vulnerability in the Change Data Capture component in Oracle Database 10.1.0.5, 10.2.0.4, and 11.1.0.6 allows remote authenticated users to affect confidentiality and integrity, related to DBMS_CDC_PUBLISH.
Exploits (1)
This Metasploit module exploits a SQL injection vulnerability in Oracle Database Server's SYS.DBMS_CDC_PUBLISH.ALTER_AUTOLOG_CHANGE_SOURCE procedure. It creates a malicious function to execute arbitrary SQL commands, leveraging the vulnerability to grant elevated privileges.