|
|
| |
| The package XDB.DBMS_XDBZ0 contains SQL injection vulnerabilities in the procedure enable_hierarchy_internal [DB01], disable_hierarchiy_internal [DB15]. Oracle fixed this problem by using bind variables and verifying table names. |
| |
Credit:
The information has been provided by Alexander Kornbrust.
The original article can be found at: http://www.red-database-security.com/advisory/oracle_sql_injection_dbms_xdbz0.html
|
| |
Vulnerable Systems:
* Oracle 9i Rel.2 - 10g Rel. 2
Patch Information:
Apply the patches for Oracle CPU October 2006.
History:
1-nov-2005 Oracle secalert was informed about both bugs.
18-oct-2006 Oracle published CPU October 2006 [DB01], [DB15]
18-oct-2006 Advisory published
CVE Information:
CVE-2006-5332, CVE-2006-5341
|
|
|
|
|
|
|
|