CVE-2006-0260: SQL Injection
Multiple unspecified vulnerabilities in Oracle Database server 9.2.0.7 and 10.1.0.5 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB05 in the (a) Data Pump component; (2) DB15 in the (b) Oracle Text component; (3) DB22 in the (c) Streams Apply component; (4) DB23 and (5) DB24 in the (d) Streams Capture component; and (6) DB26 in the (e) Streams Subcomponent. NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that DB05 involves SQL injection in the (f) LONG2VARCHAR, LONG2VCMAX, LONG2VCNT, and LONG2CLOB functions in the DBMSMETADATAUTIL package; (g) MAKEFILTER, FETCHVIEWSERROR, FETCHFILTERS, FETCHVIEWS, SETFILTERCOMMON, DOFILTERSCRIPT, SETTABLEFILTERS, and MAKEFILTERTEXT functions in the DBMSMETADATAINT package; and (h) GETPREPOSTTABLEACT function in the DBMSMETADATA package.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0260?
The severity of CVE-2006-0260 is considered critical due to multiple unspecified vulnerabilities within Oracle Database.
What versions of Oracle Database are affected by CVE-2006-0260?
CVE-2006-0260 affects Oracle Database server versions 9.2.0.7 and 10.1.0.5.
How do I fix CVE-2006-0260?
To fix CVE-2006-0260, it is recommended to upgrade the Oracle Database to a secure version provided by Oracle.
What components are impacted by CVE-2006-0260?
CVE-2006-0260 impacts the Data Pump, Oracle Text, and Streams Apply components of Oracle Database.
Is there any specific attack vector associated with CVE-2006-0260?
CVE-2006-0260 has unspecified attack vectors which may vary based on the exploit used.