Vulnerability Name: | CVE-2006-1866 (CCN-26050) | ||||||||
Assigned: | 2006-04-18 | ||||||||
Published: | 2006-04-18 | ||||||||
Updated: | 2018-10-18 | ||||||||
Summary: | Multiple unspecified vulnerabilities in Oracle Database Server 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, and other versions have unknown impact and attack vectors in the (1) Advanced Replication component, as identified by Vuln# DB01, and (2) Oracle Spatial component, as identified by Vuln# DB10. Note: details are unavailable from Oracle, but as of 20060421, they have not publicly disputed a claim by a reliable independent researcher that states that DB01 is an unknown issue in the DBMS_REPUTIL package, and DB10 is SQL injection in the INSERT_CATALOG, UPDATE_CATALOG, and DELETE_CATALOG functions of the SDO_CATALOG package. | ||||||||
CVSS v3 Severity: | 9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 9.7 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-noinfo | ||||||||
Vulnerability Consequences: | Data Manipulation | ||||||||
References: | Source: CCN Type: Full-Disclosure Mailing List, Tue Apr 18 2006 - 14:04:23 CDT Multiple critical and high risk issues in Oracle's database server Source: MITRE Type: CNA CVE-2006-1866 Source: CCN Type: SA19712 Oracle Products Multiple Vulnerabilities Source: SECUNIA Type: Patch, Vendor Advisory 19712 Source: CCN Type: SA19859 HP Oracle for OpenView Multiple Vulnerabilities Source: SECUNIA Type: Vendor Advisory 19859 Source: CCN Type: SECTRACK ID: 1015961 Oracle Database and Other Products Have Multiple Unspecified Vulnerabilities With Unspecified Impact Source: SECTRACK Type: Patch 1015961 Source: CCN Type: US-CERT VU#139049 Oracle DBMS_REPUTIL package vulnerable to SQL injection Source: CERT-VN Type: US Government Resource VU#139049 Source: CCN Type: Oracle Web site Oracle Critical Patch Update Advisory - April 2006 Source: CONFIRM Type: UNKNOWN http://www.oracle.com/technetwork/topics/security/cpuapr2006-090826.html Source: CCN Type: Red-Database-Security Web site Details Oracle Critical Patch Update April 2006 - V1.03 Source: MISC Type: UNKNOWN http://www.red-database-security.com/advisory/oracle_cpu_apr_2006.html Source: HP Type: UNKNOWN SSRT061148 Source: BID Type: Exploit 17590 Source: CCN Type: BID-17590 Oracle April 2006 Security Update Multiple Vulnerabilities Source: CCN Type: US-CERT Technical Cyber Security Alert TA06-109A Oracle Products Contain Multiple Vulnerabilities Source: CERT Type: US Government Resource TA06-109A Source: VUPEN Type: Vendor Advisory ADV-2006-1397 Source: VUPEN Type: Vendor Advisory ADV-2006-1571 Source: XF Type: UNKNOWN oracle-dbmsreputil-sql-injection(26050) Source: XF Type: UNKNOWN oracle-dbmsreputil-sql-injection(26050) Source: XF Type: UNKNOWN oracle-sdocatalog-sql-injection(26054) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Vulnerability Name: | CVE-2006-1866 (CCN-26054) | ||||||||
Assigned: | 2006-04-18 | ||||||||
Published: | 2006-04-18 | ||||||||
Updated: | 2006-04-18 | ||||||||
Summary: | Oracle Database is vulnerable to SQL injection in the MDSYS.SDO_CATALOG package (Spatial component). A remote attacker with PUBLIC permissions could send specially-crafted SQL statements to the INSERT_CATALOG, UPDATE_CATALOG, or DELETE_CATALOG procedure, which could allow the attacker to view, add, modify, or delete information in the back-end database. | ||||||||
CVSS v3 Severity: | 5.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 9.7 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:C/A:C) 8.4 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:C/A:C/E:H/RL:OF/RC:C)
5.7 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Consequences: | Data Manipulation | ||||||||
References: | Source: CCN Type: Full-Disclosure Mailing List, Tue Apr 18 2006 - 14:04:23 CDT Multiple critical and high risk issues in Oracle's database server Source: MITRE Type: CNA CVE-2006-1866 Source: CCN Type: SA19712 Oracle Products Multiple Vulnerabilities Source: CCN Type: SA19859 HP Oracle for OpenView Multiple Vulnerabilities Source: CCN Type: SECTRACK ID: 1015961 Oracle Database and Other Products Have Multiple Unspecified Vulnerabilities With Unspecified Impact Source: CCN Type: US-CERT VU#139049 Oracle DBMS_REPUTIL package vulnerable to SQL injection Source: CCN Type: Oracle Web site Oracle Critical Patch Update Advisory - April 2006 Source: CCN Type: Red-Database-Security Web site Details Oracle Critical Patch Update April 2006 - V1.03 Source: CCN Type: BID-17590 Oracle April 2006 Security Update Multiple Vulnerabilities Source: CCN Type: US-CERT Technical Cyber Security Alert TA06-109A Oracle Products Contain Multiple Vulnerabilities Source: XF Type: UNKNOWN oracle-sdocatalog-sql-injection(26054) | ||||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Vulnerability Name: | CVE-2006-1866 (CCN-39381) | ||||||||
Assigned: | 2006-04-15 | ||||||||
Published: | 2006-04-15 | ||||||||
Updated: | 2018-10-18 | ||||||||
Summary: | Multiple unspecified vulnerabilities in Oracle Database Server 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, and other versions have unknown impact and attack vectors in the (1) Advanced Replication component, as identified by Vuln# DB01, and (2) Oracle Spatial component, as identified by Vuln# DB10. Note: details are unavailable from Oracle, but as of 20060421, they have not publicly disputed a claim by a reliable independent researcher that states that DB01 is an unknown issue in the DBMS_REPUTIL package, and DB10 is SQL injection in the INSERT_CATALOG, UPDATE_CATALOG, and DELETE_CATALOG functions of the SDO_CATALOG package. | ||||||||
CVSS v3 Severity: | 9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 9.7 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:C/A:C) 7.1 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:C/A:C/E:U/RL:OF/RC:C)
6.7 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-noinfo | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-0435 Source: MITRE Type: CNA CVE-2006-1866 Source: MITRE Type: CNA CVE-2006-1867 Source: MITRE Type: CNA CVE-2006-1868 Source: MITRE Type: CNA CVE-2006-1869 Source: MITRE Type: CNA CVE-2006-1870 Source: MITRE Type: CNA CVE-2006-1871 Source: MITRE Type: CNA CVE-2006-1872 Source: MITRE Type: CNA CVE-2006-1873 Source: MITRE Type: CNA CVE-2006-1874 Source: MITRE Type: CNA CVE-2006-1875 Source: MITRE Type: CNA CVE-2006-1876 Source: MITRE Type: CNA CVE-2006-1877 Source: MITRE Type: CNA CVE-2006-1879 Source: MITRE Type: CNA CVE-2006-1880 Source: MITRE Type: CNA CVE-2006-1881 Source: MITRE Type: CNA CVE-2006-1882 Source: MITRE Type: CNA CVE-2006-1883 Source: MITRE Type: CNA CVE-2006-1884 Source: MITRE Type: CNA CVE-2006-1885 Source: MITRE Type: CNA CVE-2006-1886 Source: MITRE Type: CNA CVE-2006-1887 Source: CCN Type: Oracle Critical Patch Update - April 2006 Critical Patch Update - April 2006 Source: CCN Type: IBM Internet Security Systems X-Force Database Oracle PL/SQL Gateway SQL command execution Source: XF Type: UNKNOWN oracle-cpu-apr2006(39381) | ||||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |