CVE-2006-1871: SQL Injection
SQL injection vulnerability in Oracle Database Server 9.2.0.7 and 10.1.0.5 allows remote attackers to execute arbitrary SQL commands via the DELETEFROMTABLE function in the DBMSLOGMNRSESSION (Log Miner) package, aka Vuln# DB06.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1871?
CVE-2006-1871 is considered a high severity vulnerability due to the ability of remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2006-1871?
To fix CVE-2006-1871, it is recommended to apply the latest security patches provided by Oracle for Database Server versions 9.2.0.7 and 10.1.0.5.
Which versions of Oracle Database are affected by CVE-2006-1871?
CVE-2006-1871 affects Oracle Database Server versions 9.2.0.7 and 10.1.0.5.
What causes the vulnerability CVE-2006-1871?
CVE-2006-1871 is caused by improper handling of input in the DELETE_FROM_TABLE function in the DBMS_LOGMNR_SESSION package.
Can CVE-2006-1871 be exploited remotely?
Yes, CVE-2006-1871 can be exploited remotely by attackers to execute malicious SQL commands.