Vulnerability Name: | CVE-2006-7138 (CCN-30106) | ||||||||
Assigned: | 2006-10-17 | ||||||||
Published: | 2006-10-17 | ||||||||
Updated: | 2018-10-16 | ||||||||
Summary: | SQL injection vulnerability in wwv_flow_utilities.gen_popup_list in the WWV_FLOW_UTILITIES package for Oracle APEX/HTMLDB before 2.2 allows remote authenticated users to execute arbitrary SQL by modifying the P_LOV parameter and calculating a matching MD5 checksum for the P_LOV_CHECKSUM parameter. Note: it is likely that this issue is subsumed by CVE-2006-5351, but due to lack of details from Oracle, this cannot be proven. This vulnerability is addressed in the following product patch: http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2006.html | ||||||||
CVSS v3 Severity: | 5.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 6.0 Medium (CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P) 5.2 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P/E:H/RL:OF/RC:C)
5.7 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-89 | ||||||||
Vulnerability Consequences: | Data Manipulation | ||||||||
References: | Source: CCN Type: Full-Disclosure Mailing List, Mon Oct 23 2006 - 11:44:00 CDT SQL Injection Vulnerability in Oracle WWV_FLOW_UTILITIES Source: MITRE Type: CNA CVE-2006-5351 Source: MITRE Type: CNA CVE-2006-7138 Source: FULLDISC Type: Exploit 20061023 SQL Injection Vulnerability in Oracle WWV_FLOW_UTILITIES Source: CCN Type: SA22396 Oracle Products Multiple Vulnerabilities Source: SREASON Type: UNKNOWN 2346 Source: CCN Type: SECTRACK ID: 1017077 Oracle Database and Other Products Have Multiple Unspecified Vulnerabilities With Unspecified Impact Source: CCN Type: Oracle Critical Patch Update - October 2006 Oracle Critical Patch Update Advisory - October 2006 Source: MISC Type: Patch http://www.red-database-security.com/advisory/oracle_apex_sql_injection_wwv_flow_utilities.html Source: CCN Type: Red-Database-Security Web site Details Oracle Critical Patch Update October 2006 - V1.02 Source: MISC Type: Patch http://www.red-database-security.com/advisory/oracle_cpu_oct_2006.html Source: BUGTRAQ Type: UNKNOWN 20061023 SQL Injection Vulnerability in Oracle WWV_FLOW_UTILITIES Source: CCN Type: BID-20588 Oracle October 2006 Security Update Multiple Vulnerabilities Source: XF Type: UNKNOWN oracle-wwvflow-sql-injection(30106) Source: XF Type: UNKNOWN oracle-wwvflow-sql-injection(30106) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |