Exploitation Summary
EIP tracks 3 public exploits for CVE-2010-0904.
PoCs published by Metasploit, MC, including Metasploit module auxiliary/admin/oracle/osb_execqr3.
AI-analyzed exploit summary This Metasploit module exploits an authentication bypass in Oracle Secure Backup's login.php and a command injection vulnerability in property_box.php via the 'jlist' parameter. It supports direct command execution or a staged payload for Windows targets.
Description
Unspecified vulnerability in Oracle Secure Backup 10.3.0.1 allows remote attackers to affect integrity via unknown vectors.
Exploits (3)
This Metasploit module exploits an authentication bypass in Oracle Secure Backup's login.php and a command injection vulnerability in property_box.php via the 'jlist' parameter. It supports direct command execution or a staged payload for Windows targets.
This Metasploit module exploits an authentication bypass in Oracle Secure Backup's login.php and a command injection vulnerability in property_box.php to execute arbitrary commands. It leverages a crafted POST request to bypass authentication and inject commands via the 'jlist' parameter.
This Metasploit module exploits an authentication bypass in Oracle Secure Backup's login.php and a command injection vulnerability in property_box.php via the 'jlist' parameter. It allows arbitrary command execution on Windows systems.