First published: Fri Oct 14 2005(Updated: )
Cross-site scripting (XSS) vulnerability in iSQL*Plus (iSQLPlus) in Oracle9i Database Server Release 2 9.0.2.4 allows remote attackers to inject arbitrary web script or HTML via script in the "set markup HTML TABLE" command, which is executed when the user selects a table.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Database | =9.0.2.4-r2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3205 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
To mitigate CVE-2005-3205, users should upgrade to a version of Oracle9i that is not affected or apply any available security patches from Oracle.
CVE-2005-3205 specifically affects Oracle9i Database Server Release 2 version 9.0.2.4.
CVE-2005-3205 is a cross-site scripting (XSS) vulnerability that allows the injection of arbitrary web script or HTML.
Attackers can exploit CVE-2005-3205 by using the 'set markup HTML TABLE' command to run malicious scripts when users select a table.