Description
SQL injection vulnerability in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users to execute arbitrary SQL commands via vectors involving CREATE INDEX with a CTXSYS.CONTEXT INDEXTYPE and DBMS_STATS.GATHER_TABLE_STATS.
Remediation
References
Related Vulnerabilities
MySQL CVE-2017-10167 Vulnerability (CVE-2017-10167)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-0798)
WebLogic CVE-2020-2967 Vulnerability (CVE-2020-2967)
WordPress 3.8.x Multiple Vulnerabilities (3.8 - 3.8.15)
WordPress Plugin 404page-your smart custom 404 error page Cross-Site Request Forgery (10.3)