Multiple Operations of Data via Views (DB17, INSERT, UPDATE, DELETE, Exploit)
22 Jul. 2007
Summary
Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to have an unknown impact via SYS.DBMS_DRS in the DataGuard component (DB03), SYS.DBMS_STANDARD in the PL/SQL component (DB10), MDSYS.RTREE_IDX in the Spatial component (DB16), and SQL Compiler (DB17). The following exploit code can be used to determine whether your Oracle server is vulnerable to the vulnerabilities mentioned here.
Credit:
The information has been provided by Andrea "bunker" Purificato.
The original article can be found at: http://rawlab.mindcreations.com/