Oracle Database Server Vulnerability - CVE-2006-0265 - Vulnerability Database

Oracle Database Server Vulnerability - CVE-2006-0265

Critical
Reference: CVE-2006-0265
Title: Oracle Database Server Vulnerability
Overview:

Multiple unspecified vulnerabilities in Oracle Database server 8.1.7.4 9.0.1.5 9.2.0.7 10.1.0.5 and 10.2.0.1 have unspecified impact and attack vectors as identified by Oracle Vuln (1) DB17 in the Oracle Text component and (2) DB18 in the Program Interface Network component. NOTE: details are unavailable from Oracle but they have not publicly disputed a claim by a reliable independent researcher that states that DB17 involves SQL injection in the (a) VALIDATE_STATEMENT and BUILD_DML functions in CTXSYS.DRILOAD (b) CLEAN_DML function in CTXSYS.DRIDML (c) GET_ROWID function in CTXSYS.CTX_DOC (d) BROWSE_WORDS function in CTXSYS.CTX_QUERY and (e) ODCIINDEXTRUNCATE ODCIINDEXDROP and ODCIINDEXDELETE functions in CATINDEXMETHODS.