Back to search
CVE-2005-1197
Published: Apr 21, 2005
Modified: Aug 7, 2024
PUBLISHED
Description
SQL injection vulnerability in the SYS.DBMS_CDC_IPUBLISH.CREATE_SCN_CHANGE_SET procedure in Oracle Database Server 10g allows remote attackers to execute arbitrary SQL commands via the CHANGE_SET_NAME parameter.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20050418 [AppSecInc Team SHATTER Security Advisory] SQL Injection in CREATE_SCN_CHANGE_SET procedure
mailing-list
x_refsource_BUGTRAQ
VU#948486
third-party-advisory
x_refsource_CERT-VN
TA05-117A
third-party-advisory
x_refsource_CERT
http://www.oracle.com/technology/deploy/security/pdf/cpuapr2005.pdf
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now