CVE-2006-0265: SQL Injection
Multiple unspecified vulnerabilities in Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, and 10.2.0.1 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB17 in the Oracle Text component and (2) DB18 in the Program Interface Network component. NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that DB17 involves SQL injection in the (a) VALIDATESTATEMENT and BUILDDML functions in CTXSYS.DRILOAD; (b) CLEANDML function in CTXSYS.DRIDML; (c) GETROWID function in CTXSYS.CTXDOC; (d) BROWSEWORDS function in CTXSYS.CTXQUERY; and (e) ODCIINDEXTRUNCATE, ODCIINDEXDROP, and ODCIINDEXDELETE functions in CATINDEXMETHODS.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0265?
The severity of CVE-2006-0265 is unspecified, but it affects multiple versions of Oracle Database servers.
How do I fix CVE-2006-0265?
To fix CVE-2006-0265, it is recommended to apply any available patches provided by Oracle for the affected database versions.
Which versions of Oracle Database are affected by CVE-2006-0265?
CVE-2006-0265 affects Oracle Database versions 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, and 10.2.0.1.
What components are impacted by CVE-2006-0265?
CVE-2006-0265 impacts the Oracle Text component and the Program Interface Network component.
What are the attack vectors associated with CVE-2006-0265?
The attack vectors for CVE-2006-0265 are unspecified, highlighting the need for caution with these affected Oracle Database versions.