Multiple SQL injection vulnerabilities in the Portal DB (1) List of Values (LOVs), (2) Forms, (3) Hierarchy, and (4) XML components packages in Oracle Oracle9i Application Server 9.0.2.00 up to and including 3.0.9.8.5 allow remote malicious users to execute arbitrary SQL commands via the URL.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
oracle application server portal 3.0.9.8.5 |
||
oracle application server portal 9.0.2.3 |
||
oracle oracle9i 9.0.2.2 |
||
oracle oracle9i 9.0.2.3 |
||
oracle application server portal 9.0.2.3a |
||
oracle application server portal 9.0.2.3b |
||
oracle oracle9i 9.0.2 |
||
oracle oracle9i 9.0.2.0.0 |
||
oracle oracle9i 9.0.2.0.1 |
||
oracle oracle9i 9.0.2.1 |