dsecrg.com
http://dsecrg.com/pages/vul/show.php?id=305 CVE-2010-3591
Oracle Document Capture - Actbar2.ocx Insecure Method
Record summary
CVE-2010-3591 has a selected CVSS score of 9.3; EIP currently links 2 catalogued exploits.
Description
Unspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Internal Operations. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from the original researcher that remote attackers can overwrite or delete arbitrary files via a full pathname in the second argument to the DownloadSingleMessageToFile method in the EMPOP3Lib ActiveX component (empop3.dll).
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBOracle Document Capture - Actbar2.ocx Insecure MethodExploitDB exploitby Evdokimov DmitriyNot analyzed1 file
ExploitDBOracle Document Capture - 'empop3.dll' Insecure MethodsExploitDB exploitby Evdokimov DmitriyNot analyzed1 file
References
1042976Third-party advisory
http://secunia.com/advisories/42976 16055exploit
http://www.exploit-db.com/exploits/16055 oracle.comConfirmation
http://www.oracle.com/technetwork/topics/security/cpujan2011-194091.html 20110125 [DSECRG-11-005] Oracle Document Capture empop3.dll - insecure methodmailing list
http://www.securityfocus.com/archive/1/515959/100/0/threaded 45851vdb entry
http://www.securityfocus.com/bid/45851 1024981vdb entry
http://www.securitytracker.com/id?1024981 ADV-2011-0143vdb entry
http://www.vupen.com/english/advisories/2011/0143 oracle-document-internaloperations-code-exec(64768)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/64768 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2010-3591