CVE-2008-6869

Oramon 2.0.1 - Unauthenticated Sensitive Information Exposure via Direct Request

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-6869. PoCs published by ahmadbady.

AI-analyzed exploit summary This is a writeup describing a configuration download vulnerability in Oramon, an Oracle Database Monitoring tool. It provides a URL path to access the configuration file but lacks executable exploit code.

Description

Oramon Oracle Database Monitoring Tool 2.0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing credentials via a direct request for config/oramon.ini.

Exploits (1)

exploitdb WRITEUP VERIFIED
by ahmadbady · textwebappsphp
https://www.exploit-db.com/exploits/7286

This is a writeup describing a configuration download vulnerability in Oramon, an Oracle Database Monitoring tool. It provides a URL path to access the configuration file but lacks executable exploit code.

Classification
Writeup 80%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Theoretical
Target: Oramon (version not specified)
No auth needed
Prerequisites: Access to the target URL path
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/7286
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/46967
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/3305

Scores

EPSS 0.0620
EPSS Percentile 92.6%

Details

CWE
CWE-264
Status published
Products (1)
oramon/oramon 2.0.1
Published Jul 23, 2009
Tracked Since Feb 18, 2026