// For flags

CVE-2006-5341

 

Severity Score

9.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Multiple unspecified vulnerabilities in XMLDB component in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.2 have unknown impact and remote authenticated attack vectors, aka (1) Vuln# DB14 and (2) DB15 related to xdb.dbms_xdbz. NOTE: as of 20061023, Oracle has not disputed reports from reliable third parties that DB14 is for SQL injection in the PITRIG_DROP and PITRIG_DROPMETADATA functions in XDB_PITRIG_PKG, and DB15 is for SQL injection in DISABLE_HIERARCHY_INTERNAL in DBMS_XDBZ.

Múltiples vulnerabilidades no especificadas en el componente XMLDB en Oracle Database 9.2.0.8, 10.1.0.5 y 10.2.0.2 tiene impacto y vectores de ataque remoto autenticado remoto, también conocida como (1) Vuln# DB14 y (2) DB15 relacionado con xdb.dbms_xdbz. NOTA: a partir de 20061023, Oracle no ha disputado informes de terceras partes confiables sobre que DB14 es para inyección SQL en las funciones PITRIG_DROP y PITRIG_DROPMETADATA en XDB_PITRIG_PKG y DB15 es para inyección SQL en DISABLE_HIERARCHY_INTERNAL en DBMS_XDBZ.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2006-10-17 CVE Reserved
  • 2006-10-18 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-09-07 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Oracle
Search vendor "Oracle"
Database Server
Search vendor "Oracle" for product "Database Server"
9.2.0.7
Search vendor "Oracle" for product "Database Server" and version "9.2.0.7"
-
Affected
Oracle
Search vendor "Oracle"
Database Server
Search vendor "Oracle" for product "Database Server"
10.1.0.5
Search vendor "Oracle" for product "Database Server" and version "10.1.0.5"
-
Affected
Oracle
Search vendor "Oracle"
Database Server
Search vendor "Oracle" for product "Database Server"
10.2.0.2
Search vendor "Oracle" for product "Database Server" and version "10.2.0.2"
-
Affected