[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [rejected] Oracle exploit for CTXSYS.DRVXTABC.CREATE_TABLES and others



I wrote:
CTXSYS.DRVXTABC.CREATE_TABLES injection on Oracle DB 9i/10g (CVE-2009-1991)

Hi all,

I really apologize for the mistake. The released code about this flaw seems not working because of the "authid current_user" clause used during the creation of the DRVXTABC package.
There were some contributory causes that drive me into the wrong way.

As previously reported by Alexandr Polyakov, the injection still works but impacts only confidentiality and integrity.

Regards,
--
Andrea Purificato
http://rawlab.mindcreations.com