CVE Database
/

CVE-2006-0265

Back to search

CVE-2006-0265

Published: Jan 18, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple unspecified vulnerabilities in Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, and 10.2.0.1 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB17 in the Oracle Text component and (2) DB18 in the Program Interface Network component. NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that DB17 involves SQL injection in the (a) VALIDATE_STATEMENT and BUILD_DML functions in CTXSYS.DRILOAD; (b) CLEAN_DML function in CTXSYS.DRIDML; (c) GET_ROWID function in CTXSYS.CTX_DOC; (d) BROWSE_WORDS function in CTXSYS.CTX_QUERY; and (e) ODCIINDEXTRUNCATE, ODCIINDEXDROP, and ODCIINDEXDELETE functions in CATINDEXMETHODS.

VendorProductVersions

n/a

n/a

affected
n/a

References

22555
vdb-entry
x_refsource_OSVDB
oracle-january2006-update(24321)
vdb-entry
x_refsource_XF
18493
third-party-advisory
x_refsource_SECUNIA
ADV-2006-0323
vdb-entry
x_refsource_VUPEN
16287
vdb-entry
x_refsource_BID
22640
vdb-entry
x_refsource_OSVDB
VU#545804
third-party-advisory
x_refsource_CERT-VN
1015499
vdb-entry
x_refsource_SECTRACK
ADV-2006-0243
vdb-entry
x_refsource_VUPEN
22642
vdb-entry
x_refsource_OSVDB
18608
third-party-advisory
x_refsource_SECUNIA
22639
vdb-entry
x_refsource_OSVDB
22641
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now