Summary
This host is running Oracle database or application server and is prone to SQL command execution vulnerability.
Impact
Successful exploitation allows an attackers to send a specially-crafted HTTP request to bypass the PLSQLExclusion list and execute SQL commands on the back-end database with DBA privileges.
Impact Level: Application
Solution
Apply patches from below link,
http://www.oracle.com/technetwork/topics/security/cpuapr2006-090826.html
Insight
The flaw is due to error in Oracle PL/SQL Gateway, which fails to properly validate user-supplied HTTP requests.
Affected
Oracle Database server versions 9.2.0.7 and 10.1.0.5 Oracle Application server versions 1.0.2.2, 9.0.4.2, 10.1.2.0.2, 10.1.2.1 and 10.1.3.0.0
References
Severity
Classification
-
CVE CVE-2006-0435 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities