This application requires Javascript for optimal performance.

Oracle.SYS.DBMSMETADATA.SQL.Injection

Alias(es)

Oracle.SYS.DBMS_METADATA.Injection

Release Date

Apr 25, 2006

Severity

high

Impact

System compromise

Description

This indicates a possible attack against an SQL-Injection vulnerability in Oracle database.

The vulnerability is due to the application's failure to properly validate user-supplied data. An attacker may exploit this to acquire or modify data, or to exploit other vulnerabilities in the database.

Affected Products

Oracle Oracle9i Standard Edition 9.2.6 and earlier

Recommended Actions

Upgrade to a non-vulnerable version.

Coverage

IPS
VCM

Reference/s

http://www.securityfocus.com/bid/13238 (BugTraq)

Reference: VID-11875