SQL Injection Vulnerability in Oracle9i Application Server (2003)
A potential security vulnerability has been discovered in the Portal component of Oracle9i Application Server, Release 9.0.2. A knowledgeable, malicious and unauthenticated user can potentially inject a SQL script through a URL in order to gain unauthorized access to user data in Oracle9i Application Server. Products Affected • Oracle9i Application Server Portal Release 1, v 3.0.9.8.5 (and earlier) • Oracle9i Application Server Portal Release 2, v 9.0.2.3.0 (and earlier) - Portal version 9.0.2.6 and onwards are not vulnerable. [via]
http://www.oracle.com/technology/deploy/secur...

Tags:
sql injection,
sql,
injection,
vulnerability,
security,
oracle,
server,
application server,
application,
oracle9i, ...
Related Files
Sponsored Links
Free Download Mustek Manual, Guide, Instructions, available in PDF ebooks format.