CVE-2006-0271: SQL Injection
Unspecified vulnerability in the Upgrade & Downgrade component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB28. NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that the problem is SQL injection in the DBMSREGISTRY package in certain parameters to the (1) ISCOMPONENT, (2) GETCOMPOPTION, (3) DISABLEDDLTRIGGERS, (4) SCRIPTEXISTS, (5) COMPPATH, (6) GATHERSTATS, (7) NOTHINGSCRIPT, and (8) VALIDATECOMPONENTS functions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0271?
The severity of CVE-2006-0271 is unspecified as Oracle does not provide detailed information about the impact.
How do I fix CVE-2006-0271?
To address CVE-2006-0271, ensure that your Oracle Database server is updated to the latest version provided by Oracle.
Which Oracle Database versions are affected by CVE-2006-0271?
CVE-2006-0271 affects Oracle Database versions 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4.
Is there an official patch for CVE-2006-0271?
Oracle has not made specific patches public for CVE-2006-0271.
What components of Oracle Database are impacted by CVE-2006-0271?
CVE-2006-0271 impacts the Upgrade & Downgrade component of Oracle Database.