CVE-2006-5341
https://notcve.org/view.php?id=CVE-2006-5341
Multiple unspecified vulnerabilities in XMLDB component in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.2 have unknown impact and remote authenticated attack vectors, aka (1) Vuln# DB14 and (2) DB15 related to xdb.dbms_xdbz. NOTE: as of 20061023, Oracle has not disputed reports from reliable third parties that DB14 is for SQL injection in the PITRIG_DROP and PITRIG_DROPMETADATA functions in XDB_PITRIG_PKG, and DB15 is for SQL injection in DISABLE_HIERARCHY_INTERNAL in DBMS_XDBZ. Múltiples vulnerabilidades no especificadas en el componente XMLDB en Oracle Database 9.2.0.8, 10.1.0.5 y 10.2.0.2 tiene impacto y vectores de ataque remoto autenticado remoto, también conocida como (1) Vuln# DB14 y (2) DB15 relacionado con xdb.dbms_xdbz. NOTA: a partir de 20061023, Oracle no ha disputado informes de terceras partes confiables sobre que DB14 es para inyección SQL en las funciones PITRIG_DROP y PITRIG_DROPMETADATA en XDB_PITRIG_PKG y DB15 es para inyección SQL en DISABLE_HIERARCHY_INTERNAL en DBMS_XDBZ. • http://secunia.com/advisories/22396 http://securitytracker.com/id?1017077 http://www.databasesecurity.com/oracle/OracleOct2006-CPU-Analysis.pdf http://www.kb.cert.org/vuls/id/318764 http://www.oracle.com/technetwork/topics/security/cpuoct2006-095368.html http://www.red-database-security.com/advisory/oracle_cpu_oct_2006.html http://www.red-database-security.com/advisory/oracle_sql_injection_dbms_xdbz0.html http://www.securityfocus.com/archive/1/449110/100/0/threaded http://www.securityfoc •
CVE-2006-3702
https://notcve.org/view.php?id=CVE-2006-3702
Multiple unspecified vulnerabilities in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, and 10.2.0.2 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB06 in Export; (2) DB08, (3) DB09, (4) DB10, (5) DB11, (6) DB12, (7) DB13, (8) DB14, and (9) DBC01 for OCI; (10) DB16 for Query Rewrite/Summary Mgmt; (11) DB17, (12) DB18, (13) DB19, (14) DBC02, (15) DBC03, and (16) DBC04 for RPC; and (17) DB20 for Semantic Analysis. NOTE: as of 20060719, Oracle has not disputed third party claims that DB06 is related to "SQL injection" using DBMS_EXPORT_EXTENSION with a modified ODCIIndexGetMetadata routine and a call to GET_DOMAIN_INDEX_METADATA, in which case DB06 might be CVE-2006-2081. Múltiples vulnerabilidades no especificadas en Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, y 10.2.0.2 tienen un impacto desconocido y vectores de ataque, también conocido como Oracle Vuln# (1) DB06 en Export; (2) DB08, (3) DB09, (4) DB10, (5) DB11, (6) DB12, (7) DB13, (8) DB14, and (9) DBC01 para Query Rewrite/Summary Mgmt; (11) DB17, (12) DB18, (13) DB19, (14) DBC02, (15) DBC03, y (16) DBC04 para RPC; y(17) DB20 para Semantic Analysis. NOTA: en fecha 20060719, Oracle no ha disputado a terceros que DB06 está relacionado con la “inyección SQL” utilizando DBMS_EXPORT_EXTENSION con una rutina ODCIIndexGetMetadata y una llamada a GET_DOMAIN_INDEX_METADATA, en cuyo caso DB06 podría estar CVE-2006-2081. • http://secunia.com/advisories/21111 http://secunia.com/advisories/21165 http://securitytracker.com/id?1016529 http://www.kb.cert.org/vuls/id/932124 http://www.oracle.com/technetwork/topics/security/cpujul2006-101315.html http://www.red-database-security.com/advisory/oracle_cpu_july_2006.html http://www.red-database-security.com/exploits/oracle-sql-injection-oracle-dbms_export_extension.html http://www.securityfocus.com/archive/1/440758/100/100/threaded http://www.securityfocus.com/bid •
CVE-2006-3705
https://notcve.org/view.php?id=CVE-2006-3705
Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB21 for Statistics and (2) DB22 for Upgrade & Downgrade. NOTE: as of 20060719, Oracle has not disputed a claim by a reliable researcher that DB21 is for a local SQL injection vulnerability in SYS.DBMS_STATS, and that DB22 is for SQL injection in SYS.DBMS_UPGRADE. Múltiples vulnerabilidades no especificadas en Oracle Database 10.1.0.5 tiene un impacto desconocido y vectores de ataque, también conocido como Oracle Vuln# (1) DB21 para Statistics y (2) DB22 para Upgrade & Downgrade. NOTA: en fecha 20060719, Oracle no ha disputado este asunto por un investigador creible que DB21 es para vulnerabildades de inyección SQL local en SYS.DBMS_STATS, y que DB22 es para inyección SQL en SYS.DBMS_UPGRADE. • http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/047992.html http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/047993.html http://secunia.com/advisories/21111 http://secunia.com/advisories/21165 http://securityreason.com/securityalert/1251 http://securitytracker.com/id?1016529 http://www.oracle.com/technetwork/topics/security/cpujul2006-101315.html http://www.red-database-security.com/advisory/oracle_cpu_july_2006.html http://www.red-database-security.com/advisory/ora •
CVE-2006-3698 – Oracle 10g - SYS.KUPW$WORKER.MAIN PL / SQL Injection
https://notcve.org/view.php?id=CVE-2006-3698
Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB01 for Change Data Capture (CDC) component and (2) DB03 for Data Pump Metadata API. NOTE: as of 20060719, Oracle has not disputed a claim by a reliable researcher that DB01 is related to multiple SQL injection vulnerabilities in SYS.DBMS_CDC_IMPDP using the (a) IMPORT_CHANGE_SET, (b) IMPORT_CHANGE_TABLE, (c) IMPORT_CHANGE_COLUMN, (d) IMPORT_SUBSCRIBER, (e) IMPORT_SUBSCRIBED_TABLE, (f) IMPORT_SUBSCRIBED_COLUMN, (g) VALIDATE_IMPORT, (h) VALIDATE_CHANGE_SET, (i) VALIDATE_CHANGE_TABLE, and (j) VALIDATE_SUBSCRIPTION procedures, and that DB03 is for SQL injection in the MAIN procedure for SYS.KUPW$WORKER. Múltiples vulnerabilidades no especificadas en Oracle Database 10.1.0.5 tienen un impacto desconocido y vectores de ataque, también conocido como Oracle Vuln# (1) DB01 para el componente Change Data Capture (CDC) y (2) DB03 para Data Pump Metadata API. NOTA: en fecha de 20060719, Oracle no ha cuestionado la demanda de un investigador confiable que DB01 está relacionado con múltiples vulnerabilidades de inyección SQL en SYS.DBMS_CDC_IMPDP utilizando los procedimientos (a) IMPORT_CHANGE_SET, (b) IMPORT_CHANGE_TABLE, (c) IMPORT_CHANGE_COLUMN, (d) IMPORT_SUBSCRIBER, (e) IMPORT_SUBSCRIBED_TABLE, (f) IMPORT_SUBSCRIBED_COLUMN, (g) VALIDATE_IMPORT, (h) VALIDATE_CHANGE_SET, (i) VALIDATE_CHANGE_TABLE, y (j) VALIDATE_SUBSCRIPTION, y que DB03 es para inyección SQL en el proceso MAIN para SYS.KUPW$WORKER. • https://www.exploit-db.com/exploits/3178 https://www.exploit-db.com/exploits/3358 https://www.exploit-db.com/exploits/3375 http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/047994.html http://secunia.com/advisories/21111 http://secunia.com/advisories/21165 http://securitytracker.com/id?1016529 http://www.oracle.com/technetwork/topics/security/cpujul2006-101315.html http://www.red-database-security.com/advisory/oracle_cpu_july_2006.html http://www.red-database-security •
CVE-2006-1866
https://notcve.org/view.php?id=CVE-2006-1866
Multiple unspecified vulnerabilities in Oracle Database Server 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, and other versions have unknown impact and attack vectors in the (1) Advanced Replication component, as identified by Vuln# DB01, and (2) Oracle Spatial component, as identified by Vuln# DB10. NOTE: details are unavailable from Oracle, but as of 20060421, they have not publicly disputed a claim by a reliable independent researcher that states that DB01 is an unknown issue in the DBMS_REPUTIL package, and DB10 is SQL injection in the INSERT_CATALOG, UPDATE_CATALOG, and DELETE_CATALOG functions of the SDO_CATALOG package. Múltiples vulnerabilidades no especificadas en Oracle Database Server 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, y otras versiones tienen impacto y vectores de ataque desconocidos en el (1) componente de Replicación Avanzada, identificado por Vuln#DB01, y (2) el componente Espacial Oracle, identificado por Vuln# DB10. NOTA: los detalles son inaccesibles desde Oracle, pero en fecha 21/04/2006, no han discutido publicamente una raclamanción por un investigador independiente confiable que indique que DB01 es un asunto desconocido en el paquete de DBMS_REPUTIL, y DB10 es inyección del SQL en las funciones de INSERT_CATALOG, de UPDATE_CATALOG, y de DELETE_CATALOG del paquete SDO_CATALOG. • http://secunia.com/advisories/19712 http://secunia.com/advisories/19859 http://securitytracker.com/id?1015961 http://www.kb.cert.org/vuls/id/139049 http://www.oracle.com/technetwork/topics/security/cpuapr2006-090826.html http://www.red-database-security.com/advisory/oracle_cpu_apr_2006.html http://www.securityfocus.com/archive/1/432267/100/0/threaded http://www.securityfocus.com/bid/17590 http://www.us-cert.gov/cas/techalerts/TA06-109A.html http://www.vupen.com/english& •