|
|
| |
| The Intermedia application in Oracle 10g release 1 and 2 is vulnerable to SQL injection. |
| |
Credit:
The information has been provided by David Litchfield.
The original article can be found at:
http://www.ngssoftware.com/advisories/high-risk-vulnerability-in-oracle-ctx-doc/
|
| |
Vulnerable Systems:
* Oracle 10g release 1
* Oracle 10g release 2
The Intermedia application, owned by CTXSYS, contains a package called CTX_DOC. This package contains multiple SQL injection flaws. The following procedures on this package provide vectors for SQL injection attacks:
THEMES
GIST
TOKENS
FILTER
HIGHLIGHT
MARKUP
These can be exploited by a database user; further they can be exploited via Oracle Application Server by an attacker without a user ID and password across the Internet.
Vendor Status:
Oracle was alerted to these flaws on the 6th of June 2005. A patch has now been made available:
http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2007.html
|
|
|
|
|
|
|
|