On Mon, 2 Apr 2007, Andrea "bunker" Purificato wrote:
> [0-day] Remote Oracle DBMS_AQ.ENQUEUE exploit (10g)
Not a 0day. Just publicly released exploit code.
This is:
1. Patched.
2. Not publicly exploitable.
Gadi.
>
> Grant or revoke dba permission to unprivileged user
> Tested on "Ora
On Monday 02 April 2007 20:12, Gadi Evron wrote:
> Not a 0day. Just publicly released exploit code.
You're right, sorry for mistakes. I meant "first public exploit".
> This is:
> 1. Patched.
Yes: CPUJan2007
> 2. Not publicly exploitable.
Permission grant to public between 9.0.1.x and 10.1.0.x
[0-day] Remote Oracle DBMS_AQ.ENQUEUE exploit (10g)
Grant or revoke dba permission to unprivileged user
Tested on "Oracle Database 10g Enterprise Edition Release 10.1.0.3.0"
AUTHOR: Andrea "bunker" Purificato
http://rawlab.mindcreations.com
DATE: Mon Apr 2 11:54:22 CEST 2007