6.5
CVSSv2

CVE-2007-5508

Published: 17/10/2007 Updated: 15/10/2018
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in the CTXSYS Intermedia application for the Oracle Text component (CTX_DOC) in Oracle Database 10.1.0.5 and 10.2.0.3 allow remote authenticated users to execute arbitrary SQL commands via the (1) THEMES, (2) GIST, (3) TOKENS, (4) FILTER, (5) HIGHLIGHT, and (6) MARKUP procedures, aka DB03. NOTE: remote unauthenticated attack vectors exist when CTXSYS is used with oracle Application Server.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

oracle database server 10.2.0.3

oracle database server 10.1.0.5

Exploits

/******************************************************************/ /******* Oracle 10g CTX_DOCMARKUP SQL Injection Exploit **********/ /******************************************************************/ /************ sploit grant DBA to unprivileged user ***************/ /******************************************************************/ /**** ...