10
CVSSv2

CVE-2006-0271

Published: 18/01/2006 Updated: 20/07/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Unspecified vulnerability in the Upgrade & Downgrade component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB28. NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that the problem is SQL injection in the DBMS_REGISTRY package in certain parameters to the (1) IS_COMPONENT, (2) GET_COMP_OPTION, (3) DISABLE_DDL_TRIGGERS, (4) SCRIPT_EXISTS, (5) COMP_PATH, (6) GATHER_STATS, (7) NOTHING_SCRIPT, and (8) VALIDATE_COMPONENTS functions.

Vulnerable Product Search on Vulmon Subscribe to Product

oracle oracle8i standard 8.1.7.4

oracle database server 8.1.7.4

oracle oracle10g enterprise 10.1.0.4

oracle oracle9i enterprise 9.0.1.5

oracle oracle10g standard 10.1.0.4

oracle oracle9i standard 9.2.0.7

oracle oracle8i enterprise 8.1.7.4

oracle oracle10g personal 10.1.0.4