Oracle Database Server Vulnerability - CVE-2006-5341
Multiple unspecified vulnerabilities in XMLDB component in Oracle Database 9.2.0.8 10.1.0.5 and 10.2.0.2 have unknown impact and remote authenticated attack vectors aka (1) Vuln DB14 and (2) DB15 related to xdb.dbms_xdbz. NOTE: as of 20061023 Oracle has not disputed reports from reliable third parties that DB14 is for SQL injection in the PITRIG_DROP and PITRIG_DROPMETADATA functions in XDB_PITRIG_PKG and DB15 is for SQL injection in DISABLE_HIERARCHY_INTERNAL in DBMS_XDBZ.