Vulnerabilities > CVE-2006-2505 - SQL Injection vulnerability in Oracle Database Server Release2
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Oracle Database Server 10g Release 2 allows local users to execute arbitrary SQL queries via a reference to a malicious package in the TYPE_NAME argument in the (1) GET_DOMAIN_INDEX_TABLES or (2) GET_V2_DOMAIN_INDEX_TABLES function in the DBMS_EXPORT_EXTENSION package.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description Oracle <= 10g Release 2 (DBMS_EXPORT_EXTENSION) Local SQL Exploit. CVE-2006-2081,CVE-2006-2505. Local exploits for multiple platform id EDB-ID:1719 last seen 2016-01-31 modified 2006-04-26 published 2006-04-26 reporter N1V1Hd source https://www.exploit-db.com/download/1719/ title Oracle <= 10g Release 2 DBMS_EXPORT_EXTENSION Local SQL Exploit description Oracle 9i/10g DBMS_EXPORT_EXTENSION SQL Injection Exploit. CVE-2006-2081,CVE-2006-2505. Remote exploits for multiple platform id EDB-ID:3269 last seen 2016-01-31 modified 2007-02-05 published 2007-02-05 reporter bunker source https://www.exploit-db.com/download/3269/ title Oracle 9i/10g DBMS_EXPORT_EXTENSION SQL Injection Exploit