Multiple SQL-injection vulnerabilities in Oracle 9i Application Server and RDBMS
Multiple SQL-injection vulnerabilities in Application Server and RDBMS can result in remote compromise of the vulnerable server.
November 5, 2003
Reported November 5, 2003, by NGSSoftware.
VERSIONS AFFECTED
Oracle9i Application Server Releases 1 and 2
Oracle Relational Database Management System (RDBMS)
DESCRIPTION
Multiple SQL-injection vulnerabilities in Application Server and RDBMS can result in remote compromise of the vulnerable server. Many of the Procedural Level (PL)/SQL packages and procedures that Application Server uses are vulnerable to SQL injection. An unauthenticated attacker can exploit these vulnerabilities to gain access from the Internet to all data in the database.
VENDOR RESPONSE
Oracle has released analert regarding this vulnerability.
CREDIT
Discovered byNGSSoftware.
About the Author
You May Also Like