CVE-2006-3705: SQL Injection
Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB21 for Statistics and (2) DB22 for Upgrade & Downgrade. NOTE: as of 20060719, Oracle has not disputed a claim by a reliable researcher that DB21 is for a local SQL injection vulnerability in SYS.DBMSSTATS, and that DB22 is for SQL injection in SYS.DBMSUPGRADE.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-3705?
The exact severity of CVE-2006-3705 is unspecified, but it involves multiple vulnerabilities with potentially significant impact.
How can I patch CVE-2006-3705?
To address CVE-2006-3705, ensure your Oracle Database is updated to a version that mitigates the vulnerabilities.
What types of attacks are associated with CVE-2006-3705?
CVE-2006-3705 includes vulnerabilities related to local SQL injection, though the exact attack vectors remain unspecified.
Which version of Oracle Database is affected by CVE-2006-3705?
CVE-2006-3705 affects version 10.1.0.5 of Oracle Database.
Are there any known exploits for CVE-2006-3705?
There are currently no publicly available exploits specifically associated with CVE-2006-3705, but vulnerabilities may be leveraged in specific contexts.