CVE-2006-1874: SQL Injection
Unspecified vulnerability in Oracle Database Server 8.1.7.4, 9.0.1.5, and 9.2.0.6 has unknown impact and attack vectors in the Oracle Spatial component, aka Vuln# DB09. NOTE: Oracle has not disputed reliable claims that this issue is SQL injection in MDSYS.PRVTIDX using the (1) EXECUTEINSERT, (2) EXECUTEDELETE, (3) EXECUTEUPDATE, (4) EXECUTE UPDATE, and (5) CRTDUMMY functions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1874?
The severity of CVE-2006-1874 is currently unknown due to unspecified impact and attack vectors.
How do I fix CVE-2006-1874?
To address CVE-2006-1874, it is recommended to upgrade to a patched version of Oracle Database that is not affected by this vulnerability.
Which versions of Oracle Database are affected by CVE-2006-1874?
CVE-2006-1874 affects Oracle Database Server versions 8.1.7.4, 9.0.1.5, and 9.2.0.6.
Is there any known exploit for CVE-2006-1874?
There are no specific details available regarding known exploits for CVE-2006-1874, as the impact and attack vectors remain unspecified.
What component of Oracle Database is impacted by CVE-2006-1874?
CVE-2006-1874 impacts the Oracle Spatial component of the Oracle Database.