AOH :: HP Unsorted S :: TB10481.HTM

SYS.DBMS_UPGRADE_INTERNAL SQL injection



Advisory: SQL Injection in package SYS.DBMS_UPGRADE_INTERNAL
Advisory: SQL Injection in package SYS.DBMS_UPGRADE_INTERNAL



Name 	SQL Injection in package SYS.DBMS_UPGRADE_INTERNAL (6980753) [DB07]
Systems Affected 	Oracle 8i-10g Rel. 2
Severity 	        High Risk
Category 	        SQL Injection
Vendor URL 	 http://www.oracle.com/ 
Author     	        Alexander Kornbrust (ak at red-database-security.com)
Advisory        	17 April 2007 (V 1.00)


Details
#######
The package DBMS_UPGRADE_INTERNAL contains SQL injection vulnerabilities.

This advisory is available at
 


Patch Information
#################
Apply the patches for Oracle CPU April 2007.


History
#######
01-nov-2005 Oracle secalert was informed
02-nov-2005 Bug confirmed
17-apr-2007 Oracle published CPU April 2007 [DB07]
17-apr-2007 Advisory published


Additional Information
######################
An analysis of the Oracle CPU April 2007 is available here 
 

This document will be updated during the next few days and weeks with the latest information.


(c) 2007 by Red-Database-Security GmbH
--
http://www.red-database-security.com 

The entire AOH site is optimized to look best in Firefox® 3 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2014 AOH
We do not send spam. If you have received spam bearing an artofhacking.com email address, please forward it with full headers to abuse@artofhacking.com.