CWE
89
Advisory Published
Updated

CVE-2006-3702: SQL Injection

First published: Fri Jul 21 2006(Updated: )

Multiple unspecified vulnerabilities in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, and 10.2.0.2 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB06 in Export; (2) DB08, (3) DB09, (4) DB10, (5) DB11, (6) DB12, (7) DB13, (8) DB14, and (9) DBC01 for OCI; (10) DB16 for Query Rewrite/Summary Mgmt; (11) DB17, (12) DB18, (13) DB19, (14) DBC02, (15) DBC03, and (16) DBC04 for RPC; and (17) DB20 for Semantic Analysis. NOTE: as of 20060719, Oracle has not disputed third party claims that DB06 is related to "SQL injection" using DBMS_EXPORT_EXTENSION with a modified ODCIIndexGetMetadata routine and a call to GET_DOMAIN_INDEX_METADATA, in which case DB06 might be CVE-2006-2081.

Credit: cve@mitre.org

Affected SoftwareAffected VersionHow to fix
Oracle Database=10.2.0.2
Oracle Database=8.1.7.4
Oracle Database=9.2.0.7
Oracle Database=10.1.0.5

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What are the vulnerabilities associated with CVE-2006-3702?

    CVE-2006-3702 includes multiple unspecified vulnerabilities in various versions of Oracle Database with unknown impacts and attack vectors.

  • Which versions of Oracle Database are affected by CVE-2006-3702?

    CVE-2006-3702 affects Oracle Database versions 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, and 10.2.0.2.

  • What is the potential impact of the vulnerabilities in CVE-2006-3702?

    The specific impact of the vulnerabilities in CVE-2006-3702 is unknown.

  • How can organizations mitigate the risks of CVE-2006-3702?

    Organizations should apply patches and updates released by Oracle for the affected database versions to mitigate the risks associated with CVE-2006-3702.

  • Is there a known exploit for CVE-2006-3702?

    As of now, there are no publicly known exploit details for CVE-2006-3702.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203