module

Oracle Secure Backup Authentication Bypass/Command Injection Vulnerability

Disclosed
2010-07-13
Created
2018-05-30

Description

This module exploits an authentication bypass vulnerability
in login.php in order to execute arbitrary code via a command injection
vulnerability in property_box.php. This module was tested
against Oracle Secure Backup version 10.3.0.1.0 (Win32).

Author

MC mc@metasploit.com

Module Options

To display the available options, load the module within the Metasploit console and run the commands ‘show options’ or ‘show advanced’:


msf > use auxiliary/admin/oracle/osb_execqr3
msf auxiliary(osb_execqr3) > show actions
...actions...
msf auxiliary(osb_execqr3) > set ACTION < action-name >
msf auxiliary(osb_execqr3) > show options
...show and set options...
msf auxiliary(osb_execqr3) > run

Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.