Oracle 10g SQL Injection...

- AV AC AU C I A
发布: 2009-02-18
修订: 2025-04-13

This Metasploit module will escalate a Oracle DB user to MDSYS by exploiting a SQL injection bug in the MDSYS.SDO_TOPO_DROP_FTBL trigger. After that, the exploit escalates the user to DBA using "CREATE ANY TRIGGER" privilege given to the MDSYS user by creating an evil trigger in system scheme (2-stage attack).

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息