module
Oracle Secure Backup Authentication Bypass/Command Injection Vulnerability
Disclosed | Created |
---|---|
2010-07-13 | 2018-05-30 |
Disclosed
2010-07-13
Created
2018-05-30
Description
This module exploits an authentication bypass vulnerability
in login.php in order to execute arbitrary code via a command injection
vulnerability in property_box.php. This module was tested
against Oracle Secure Backup version 10.3.0.1.0 (Win32).
in login.php in order to execute arbitrary code via a command injection
vulnerability in property_box.php. This module was tested
against Oracle Secure Backup version 10.3.0.1.0 (Win32).
Author
MC mc@metasploit.com
References
Module Options
To display the available options, load the module within the Metasploit console and run the commands ‘show options’ or ‘show advanced’:

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.