First published: Sun Dec 31 2000(Updated: )
SQL injection vulnerability in mod_sql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the query string of the URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Application Server | <=3.0.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-1236 is classified as a high-severity SQL injection vulnerability.
To fix CVE-2000-1236, upgrade to Oracle Internet Application Server version 3.0.8 or later.
CVE-2000-1236 affects users of Oracle Internet Application Server versions 3.0.7 and earlier.
CVE-2000-1236 allows attackers to execute arbitrary SQL commands through crafted URL query strings.
Mitigation measures for CVE-2000-1236 include applying the latest security patches and using input validation techniques.