{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-04T07:57:37.203","vulnerabilities":[{"cve":{"id":"CVE-2005-2371","sourceIdentifier":"cve@mitre.org","published":"2005-07-26T04:00:00.000","lastModified":"2026-04-16T00:27:16.627","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Directory traversal vulnerability in Oracle Reports 6.0, 6i, 9i, and 10g allows remote attackers to overwrite arbitrary files via (1) \"..\", (2) Windows drive letter (C:), and (3) absolute path sequences in the desname parameter.  NOTE: this issue was probably fixed by REP06 in CPU Jan 2006, in which case it overlaps CVE-2006-0289."},{"lang":"es","value":"Vulnerabilidad desconocida en Oracle Reports 6.0, 6i, 9i, y 10g permite que atacantes remotos sobreescriban ficheros arbitrarios mediante el parámetro \"desname\"."}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:reports:6.0:*:*:*:*:*:*:*","matchCriteriaId":"0A0E0107-3398-4479-88C4-E797CEAF1663"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:reports:6i:*:*:*:*:*:*:*","matchCriteriaId":"20A7C259-2705-49B4-843E-CD4B92A8DAC9"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:reports:9i:*:*:*:*:*:*:*","matchCriteriaId":"D3672EE5-FAA7-4665-B2B9-48A1865F0C97"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:reports:10g:*:*:*:*:*:*:*","matchCriteriaId":"F3B768FF-F7F9-41E1-BFA5-6D41895089CE"}]}]}],"references":[{"url":"http://marc.info/?l=bugtraq&m=112180096507467&w=2","source":"cve@mitre.org"},{"url":"http://secunia.com/advisories/18493","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"http://secunia.com/advisories/18608","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"http://securitytracker.com/id?1014524","source":"cve@mitre.org"},{"url":"http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html","source":"cve@mitre.org"},{"url":"http://www.red-database-security.com/advisory/oracle_reports_overwrite_any_file.html","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"http://www.securityfocus.com/archive/1/422257/30/7430/threaded","source":"cve@mitre.org"},{"url":"http://www.securityfocus.com/bid/14309","source":"cve@mitre.org"},{"url":"http://www.vupen.com/english/advisories/2006/0323","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24321","source":"cve@mitre.org"},{"url":"http://marc.info/?l=bugtraq&m=112180096507467&w=2","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://secunia.com/advisories/18493","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"http://secunia.com/advisories/18608","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"http://securitytracker.com/id?1014524","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.red-database-security.com/advisory/oracle_reports_overwrite_any_file.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"http://www.securityfocus.com/archive/1/422257/30/7430/threaded","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securityfocus.com/bid/14309","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.vupen.com/english/advisories/2006/0323","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24321","source":"af854a3a-2127-422b-91ae-364da2661108"}]}}]}