VYPR
Unrated severityNVD Advisory· Published Jul 26, 2005· Updated Apr 16, 2026

CVE-2005-2371

CVE-2005-2371

Description

Directory traversal vulnerability in Oracle Reports 6.0, 6i, 9i, and 10g allows remote attackers to overwrite arbitrary files via (1) "..", (2) Windows drive letter (C:), and (3) absolute path sequences in the desname parameter. NOTE: this issue was probably fixed by REP06 in CPU Jan 2006, in which case it overlaps CVE-2006-0289.

Affected products

4
  • cpe:2.3:a:oracle:reports:10g:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:oracle:reports:10g:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:reports:6.0:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:reports:6i:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:reports:9i:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

10

News mentions

0

No linked articles in our index yet.