PDA

View Full Version : Oracle Application Express Privilege Escalation Vulnerability



newsbot
17-04-2008, 01:57 AM
Oracle Application Express (http://www.oracle.com/technology/products/database/application_express/index.html) (Oracle APEX), formerly called HTML DB, is "a rapid web application development tool for the Oracle database". Local exploitation of a design error vulnerability in Oracle Corp.'s Application Express web application development tool allows attackers to gain elevated privileges.

http://www.securiteam.com/unixfocus/5QP0I1PO0O.html