Vulnerabilities > CVE-2003-1193 - Unspecified vulnerability in Oracle Application Server Portal and Oracle9I
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN oracle
nessus
Summary
Multiple SQL injection vulnerabilities in the Portal DB (1) List of Values (LOVs), (2) Forms, (3) Hierarchy, and (4) XML components packages in Oracle Oracle9i Application Server 9.0.2.00 through 3.0.9.8.5 allow remote attackers to execute arbitrary SQL commands via the URL.
Vulnerable Configurations
Nessus
NASL family | Databases |
NASL id | ORACLE9I_PORTALDEMO_ORGCHART.NASL |
description | It is possible to access a demo (PORTAL_DEMO.ORG_CHART) script on the remote host. Access to these pages should be restricted because it may be possible to abuse this demo for SQL Injection attacks. Additional components of the Portal have been reported as vulnerable to SQL injection attacks but Nessus has not tested for these. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11918 |
published | 2003-11-09 |
reporter | This script is Copyright (C) 2003-2018 Frank Berger. |
source | https://www.tenable.com/plugins/nessus/11918 |
title | Oracle PORTAL_DEMO.ORG_CHART SQL Injection |
code |
|
References
- http://otn.oracle.com/deploy/security/pdf/2003alert61.pdf
- http://otn.oracle.com/deploy/security/pdf/2003alert61.pdf
- http://www.securityfocus.com/archive/1/343520
- http://www.securityfocus.com/archive/1/343520
- http://www.securityfocus.com/bid/8966
- http://www.securityfocus.com/bid/8966
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13593
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13593