Description
Extproc in Oracle 9i and 10g does not require authentication to load a library or execute a function, which allows local users to execute arbitrary commands as the Oracle user.
Remediation
References
Related Vulnerabilities
WordPress Plugin Live Chat Unlimited Cross-Site Scripting (2.8.3)
Plone CMS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-5497)
Jetty CVE-2020-27218 Vulnerability (CVE-2020-27218)
Joomla! Core PHP Object Injection (2.5.4 - 3.8.12)
WordPress Plugin Gallery Master-Responsive Photo Galleries & Albums Cross-Site Scripting (1.0.22)