CVE-2006-1866: SQL Injection
Multiple unspecified vulnerabilities in Oracle Database Server 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, and other versions have unknown impact and attack vectors in the (1) Advanced Replication component, as identified by Vuln# DB01, and (2) Oracle Spatial component, as identified by Vuln# DB10. NOTE: details are unavailable from Oracle, but as of 20060421, they have not publicly disputed a claim by a reliable independent researcher that states that DB01 is an unknown issue in the DBMSREPUTIL package, and DB10 is SQL injection in the INSERTCATALOG, UPDATECATALOG, and DELETECATALOG functions of the SDOCATALOG package.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1866?
The severity of CVE-2006-1866 is currently unspecified and requires further investigation to determine its impact.
How do I fix CVE-2006-1866?
To fix CVE-2006-1866, it is recommended to apply the latest security patches and updates provided by Oracle for affected database server versions.
Which Oracle Database versions are affected by CVE-2006-1866?
CVE-2006-1866 affects Oracle Database Server versions 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.5 among others.
What components are vulnerable in CVE-2006-1866?
The vulnerable components identified in CVE-2006-1866 are the Advanced Replication and Oracle Spatial components.
Can CVE-2006-1866 be exploited remotely?
The exact attack vectors for CVE-2006-1866 are unknown, making it difficult to determine if remote exploitation is possible.