The manual installation of Oracle HTML DB (HTMLDB) 1.3 through 1.3.6 stores the SYS password in install.lst in plaintext, which allows local users to gain privileges.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Html_db | Oracle | 1.3 (including) | 1.3 (including) |
Html_db | Oracle | 1.3.6 (including) | 1.3.6 (including) |