The Intermedia application, owned by CTXSYS, contains a package called CTX_DOC. This package contains multiple SQL injection flaws. The following procedures on this package provide vectors for SQL injection attacks: THEMES
GIST
TOKENS
FILTER
HIGHLIGHT
MARKUP
These can be exploited by a database user; further they can be exploited via Oracle Application Server by an attacker without a user ID and password across the Internet.