Vulnerabilities > Oracle > Apex > 2.1

DATE CVE VULNERABILITY TITLE RISK
2007-07-18 CVE-2007-3860 SQL-Injection vulnerability in Apex
Unspecified vulnerability in Oracle Application Express (formerly Oracle HTML DB) 2.2.0.00.32 up to 3.0.0.00.20 allows developers to have an unknown impact via unknown attack vectors, aka APEX01.
network
low complexity
oracle
7.5
2007-03-07 CVE-2006-7158 Cross-Site Scripting vulnerability in Oracle Apex 2.0/2.1/2.2
Cross-site scripting (XSS) vulnerability in Oracle Application Express (APEX) before 2.2.1, aka Oracle HTML DB, allows remote attackers to inject arbitrary web script or HTML via the NOTIFICATION_MSG parameter.
network
oracle
4.3
2007-03-07 CVE-2006-7138 SQL Injection vulnerability in Oracle Apex 2.0/2.1
SQL injection vulnerability in wwv_flow_utilities.gen_popup_list in the WWV_FLOW_UTILITIES package for Oracle APEX/HTMLDB before 2.2 allows remote authenticated users to execute arbitrary SQL by modifying the P_LOV parameter and calculating a matching MD5 checksum for the P_LOV_CHECKSUM parameter.
network
oracle CWE-89
6.0