Lucene search

K
cveMitreCVE-2006-0548
HistoryFeb 04, 2006 - 2:02 a.m.

CVE-2006-0548

2006-02-0402:02:00
mitre
web.nvd.nist.gov
28
cve-2006-0548
sql injection
oracle text
oracle database 10g
remote attackers
arbitrary commands

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.7

Confidence

Low

EPSS

0.017

Percentile

87.8%

SQL injection vulnerability in the Oracle Text component of Oracle Database 10g, and possibly earlier versions, might allow remote attackers to execute arbitrary SQL commands via unknown vectors. NOTE: due to the lack of relevant details from the Oracle advisory, a separate CVE is being created since it cannot be conclusively proven that this issue has been addressed by Oracle. It is possible that this is the same issue as Oracle Vuln# DB15 from the January 2006 CPU, in which case this would be subsumed by CVE-2006-0260.

Affected configurations

Nvd
Node
oracledatabase_serverMatch10.1.0.4.2r1
VendorProductVersionCPE
oracledatabase_server10.1.0.4.2cpe:2.3:a:oracle:database_server:10.1.0.4.2:r1:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.7

Confidence

Low

EPSS

0.017

Percentile

87.8%