Strike ID:
E12-4bh01
CVSS:
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
False Positive:
f
Variants:
3
Year:
2012

Description

This strike exploits a vulnerability in the Oracle WebCenter Forms Recognition ActiveX control. A lack of path validation in Save method allows the remote attacker to potentially execute arbitrary code.

CVE

OSVDB

81367