Back

CVE-2005-2371

Directory traversal vulnerability in Oracle Reports 6.0, 6i, 9i, and 10g allows remote attackers to overwrite arbitrary files via (1) "..", (2) Windows drive letter (C:), and (3) absolute path sequences in the desname parameter. NOTE: this issue was probably fixed by REP06 in CPU Jan 2006, in which case it overlaps CVE-2006-0289.

Published: Jul 26, 2005 Modified: Jun 16, 2026
CWE-22

CVSS Metrics

Affected Products (4)

Vendor Product Version
oracle reports 6.0
oracle reports 6i
oracle reports 9i
oracle reports 10g

GitHub Security Advisory GHSA-762j-f7hq-mp7h

Directory traversal vulnerability in Oracle Reports 6.0, 6i, 9i, and 10g allows remote attackers...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 22.29%

Top 3% most likely to be exploited

Threat Score 26.7 / 100

Data Sources

NVD EPSS GitHub