[Full-disclosure] Full-Disclosure Digest, Vol 33, Issue 1
Joxean Koret
joxeankoret at yahoo.es
Thu Nov 1 14:36:32 GMT 2007
Hi,
You're wrong. First of all, yes, is a preauth sql injection in an "admin
console" but, if you have privileges to connect to the Oracle Financials
instance, even as a normal unprivileged user, you have sufficient
privileges to access it. You don't need to have assigned the SYSADMIN
responsability.
And second, there are many ways to bypass authentication in Oracle
E-Business Suite, at least in version 11i, I'm not sure if the same
problems applies to R12. I can't release more details right now.
Thanks,
Joxean Koret
On jue, 2007-11-01 at 12:00 +0000,
full-disclosure-request at lists.grok.org.uk wrote:
>
> Message: 8
> Date: Wed, 31 Oct 2007 22:55:36 -0500
> From: reepex <reepex at gmail.com>
> Subject: Re: [Full-disclosure] ZDI-07-058: Oracle E-Business Suite SQL
> Injection Vulnerability
> To: "zdi-disclosures at 3com.com" <zdi-disclosures at 3com.com>,
> full-disclosure at lists.grok.org.uk
> Message-ID:
> <e9d9d4020710312055q417f681dw70d706ae81d03ef5 at mail.gmail.com>
> Content-Type: text/plain; charset=ISO-8859-1
>
> post auth sql injection in random admin console - lulz
>
> On 10/31/07, zdi-disclosures at 3com.com <zdi-disclosures at 3com.com>
> wrote:
> > The specific flaw exists in the okxLOV.jsp page in the
> Administration
> > console.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 191 bytes
Desc: This is a digitally signed message part
Url : http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20071101/63f35565/attachment.bin
Full-Disclosure is hosted and sponsored by Secunia.