CVE-2005-3205: XSS
Cross-site scripting (XSS) vulnerability in iSQLPlus (iSQLPlus) in Oracle9i Database Server Release 2 9.0.2.4 allows remote attackers to inject arbitrary web script or HTML via script in the "set markup HTML TABLE" command, which is executed when the user selects a table.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2005-3205?
CVE-2005-3205 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2005-3205?
To mitigate CVE-2005-3205, users should upgrade to a version of Oracle9i that is not affected or apply any available security patches from Oracle.
What software is impacted by CVE-2005-3205?
CVE-2005-3205 specifically affects Oracle9i Database Server Release 2 version 9.0.2.4.
What type of vulnerability is CVE-2005-3205?
CVE-2005-3205 is a cross-site scripting (XSS) vulnerability that allows the injection of arbitrary web script or HTML.
How can attackers exploit CVE-2005-3205?
Attackers can exploit CVE-2005-3205 by using the 'set markup HTML TABLE' command to run malicious scripts when users select a table.