Vulnerability CVE-2003-1193


Published: 2003-11-03   Modified: 2012-02-12

Description:
Multiple SQL injection vulnerabilities in the Portal DB (1) List of Values (LOVs), (2) Forms, (3) Hierarchy, and (4) XML components packages in Oracle Oracle9i Application Server 9.0.2.00 through 3.0.9.8.5 allow remote attackers to execute arbitrary SQL commands via the URL.

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Oracle -> Application server portal 
Oracle -> Oracle9i 

 References:
http://www.securityfocus.com/archive/1/343520
http://otn.oracle.com/deploy/security/pdf/2003alert61.pdf
http://xforce.iss.net/xforce/xfdb/13593
http://www.securityfocus.com/bid/8966

Copyright 2024, cxsecurity.com

 

Back to Top