pl sql software vulnerabilities
vulnerabilities.aspcode.net
Searching pl sql software vulnerabilities
Buffer overflow in PL/SQL Apache module in Orac
Application
|
arbitrary
|
attackers
|
overflow
|
request
|
execute
|
allows
|
remote
|
Apache
|
PL/SQL
|
Buffer
|
Server
|
Oracle
|
module
|
help
|
page
|
code
|
long
|
via
|
Buffer overflow in PL/SQL Apache module in Oracle 9i Application Server allows remote attackers to execute arbitrary code via a long request for a help page.
Directory traversal vulnerability in PL/SQL Apa
vulnerability
|
Application
|
information
|
Directory
|
sensitive
|
traversal
|
attackers
|
encoded
|
access
|
double
|
remote
|
module
|
Apache
|
PL/SQL
|
Server
|
allows
|
Oracle
|
URL
|
via
|
Directory traversal vulnerability in PL/SQL Apache module in Oracle Oracle 9i Application Server allows remote attackers to access sensitive information via a double encoded URL with .. (dot dot) sequences.
Buffer overflows in PL/SQL module 3.0.9.8.2 in
overflows
|
module
|
PL/SQL
|
Buffer
|
Buffer overflows in PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allow remote attackers to cause a denial of service or execute arbitrary code via (1) a long help page request without a dadname, which overflows the resulting HTTP Location header, (2) a long HTTP request to the plsql module, (3) a long password in the HTTP Authorization, (4) a long Access Descriptor (DAD) password in the addadd form, or (5) a long cache directory name.
PL/SQL module 3.0.9.8.2 in Oracle 9i Applicatio
module
|
PL/SQL
|
PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to obtain sensitive information via the OWA_UTIL stored procedures (1) OWA_UTIL.signature, (2) OWA_UTIL.listprint, or (3) OWA_UTIL.show_query_columns.
The default configuration of the PL/SQL Gateway
administration
|
authentication
|
configuration
|
Application
|
privileges
|
attackers
|
interface
|
settings
|
default
|
Gateway
|
remote
|
allows
|
PL/SQL
|
Server
|
Oracle
|
modify
|
which
|
gain
|
102x
|
uses
|
null
|
web
|
DAD
|
The default configuration of the PL/SQL Gateway web administration interface in Oracle 9i Application Server 1.0.2.x uses null authentication, which allows remote attackers to gain privileges and modify DAD settings.
PL/SQL module 3.0.9.8.2 in Oracle 9i Applicatio
module
|
PL/SQL
|
PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to bypass authentication for a Database Access Descriptor (DAD) by modifying the URL to reference an alternate DAD that already has valid credentials.
PL/SQL module 3.0.9.8.2 in Oracle 9i Applicatio
module
|
PL/SQL
|
PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to cause a denial of service (crash) via an HTTP Authorization header without an authentication type.
Cross-site scripting (XSS) vulnerability in the
Cross-site
|
scripting
|
Cross-site scripting (XSS) vulnerability in the htp PL/SQL package for Oracle 9i Application Server (9iAS) allows remote attackers to inject arbitrary web script or HTML via the cbuf parameter to htp.print.
Format string vulnerability in the PL/SQL modul
vulnerability
|
Application
|
Oracle
|
Server
|
module
|
Format
|
string
|
PL/SQL
|
Format string vulnerability in the PL/SQL module for Oracle 9i Application Server (9iAS) allows remote attackers to execute arbitrary code via unknown vectors, possibly the web-based administration interface.
Unknown vulnerability in Oracle E-Business Suit
vulnerability
|
Applications
|
unauthorized
|
procedures
|
E-Business
|
attackers
|
modifying
|
execute
|
Unknown
|
through
|
PL/SQL
|
Oracle
|
allows
|
remote
|
Suite
|
11i6
|
11i1
|
URL
|
Unknown vulnerability in Oracle E-Business Suite 11i.1 through 11i.6 allows remote attackers to execute unauthorized PL/SQL procedures by modifying the Oracle Applications URL.
Format string vulnerability in the administrati
administrative
|
vulnerability
|
Application
|
module
|
Oracle
|
PL/SQL
|
Format
|
string
|
Server
|
pages
|
Format string vulnerability in the administrative pages of the PL/SQL module for Oracle Application Server 4.0.8 and 4.0.8 2 allows remote attackers to execute arbitrary code.
Stack-based buffer overflow in the PL/SQL EXTPR
functionality
|
authenticated
|
Stack-based
|
arbitrary
|
Oracle9i
|
Database
|
overflow
|
execute
|
Release
|
library
|
EXTPROC
|
PL/SQL
|
buffer
|
Oracle
|
allows
|
users
|
cases
|
long
|
name
|
some
|
code
|
via
|
Stack-based buffer overflow in the PL/SQL EXTPROC functionality for Oracle9i Database Release 2 and 1, and Oracle 8i, allows authenticated database users, and arbitrary database users in some cases, to execute arbitrary code via a long library name.
The PL/SQL module for the Oracle HTTP Server in
WE8ISO8859P1
|
restrictions
|
Application
|
conversions
|
improperly
|
procedures
|
characters
|
sequences
|
character
|
attackers
|
converted
|
properly
|
perform
|
certain
|
encoded
|
bypass
|
module
|
PL/SQL
|
access
|
Oracle
|
Server
|
remote
|
allows
|
"%FF"
|
using
|
which
|
does
|
HTTP
|
10g
|
"Y"
|
via
|
URL
|
set
|
not
|
The PL/SQL module for the Oracle HTTP Server in Oracle Application Server 10g, when using the WE8ISO8859P1 character set, does not perform character conversions properly, which allows remote attackers to bypass access restrictions for certain procedures via an encoded URL with "%FF" encoded sequences that are improperly converted to "Y" characters.
Multiple SQL injection vulnerabilities in PL/SQ
vulnerabilities
|
procedures
|
privileges
|
arbitrary
|
attackers
|
injection
|
commands
|
Multiple
|
execute
|
definer
|
remote
|
rights
|
PL/SQL
|
Oracle
|
allow
|
gain
|
via
|
SQL
|
10g
|
run
|
Multiple SQL injection vulnerabilities in PL/SQL procedures that run with definer rights in Oracle 9i and 10g allow remote attackers to execute arbitrary SQL commands and gain privileges via (1) DBMS_EXPORT_EXTENSION, (2) WK_ACL.GET_ACL, (3) WK_ACL.STORE_ACL, (4) WK_ADM.COMPLETE_ACL_SNAPSHOT, (5) WK_ACL.DELETE_ACLS_WITH_STATEMENT, or (6) DRILOAD.VALIDATE_STMT.
Unspecified vulnerability in the PL/SQL compone
vulnerability
|
Unspecified
|
component
|
Database
|
Server
|
PL/SQL
|
Oracle
|
Unspecified vulnerability in the PL/SQL component in Oracle Database Server 9i up to 10.1.0.4 has unknown impact and attack vectors, aka Oracle Vuln# DB01.
Unspecified vulnerability in xdb.dbms_xdbz in t
vulnerability
|
xdbdbms_xdbz
|
Unspecified
|
component
|
Database
|
Oracle
|
XMLDB
|
Unspecified vulnerability in xdb.dbms_xdbz in the XMLDB component for Oracle Database 9.2.0.6 and 10.1.0.4 has unknown impact and remote authenticated attack vectors, aka Vuln# DB01. NOTE: as of Monday, October 23, 2006, Oracle has not disputed reports from reliable third parties that DB01 is for PL/SQL injection in the ENABLE_HIERARCHY_INTERNAL procedure.
Unspecified vulnerability in Oracle Spatial com
vulnerability
|
Unspecified
|
component
|
Database
|
Spatial
|
Oracle
|
Unspecified vulnerability in Oracle Spatial component in Oracle Database 10.2.0.2 has unknown impact and remote authenticated attack vectors related to "create session" and "create procedure" privileges, aka Vuln# DB02. NOTE: as of Monday, October 23, 2006, Oracle has not disputed reports from reliable third parties that DB02 is for SQL injection in the SDO_DROP_USER_BEFORE package using a Trigger for a DROP USER statement in an anonymous PL/SQL block.
Multiple unspecified vulnerabilities in the Cha
vulnerabilities
|
unspecified
|
Multiple
|
Capture
|
Change
|
Data
|
Multiple unspecified vulnerabilities in the Change Data Capture (CDC) component in Oracle Database 9.2.0.7, 10.1.0.5, and have unknown impact and remote authenticated attack vectors related to (1) sys.dbms_cdc_ipublish (Vuln# DB05) and (2) sys.dbms_cdc_isubscribe (DB06). NOTE: as of Monday, October 23, 2006, Oracle has not disputed reports from reliable third parties that DB05 is for SQL injection in CREATE_CHANGE_TABLE and CHANGE_TABLE_TRIGGER, and DB06 is for PL/SQL injection in the PREPARE_UNBOUNDED_VIEW procedure.
Multiple SQL injection vulnerabilities in login
vulnerabilities
|
arbitrary
|
injection
|
attackers
|
loginphp
|
commands
|
Multiple
|
execute
|
remote
|
pL-PHP
|
allow
|
beta
|
via
|
SQL
|
Multiple SQL injection vulnerabilities in login.php in pL-PHP beta 0.9 allow remote attackers to execute arbitrary SQL commands via the (1) login or (2) pass parameter.
Multiple unspecified vulnerabilities in Oracle
vulnerabilities
|
unspecified
|
Database
|
Multiple
|
Oracle
|
9015+
|
Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to have an unknown impact via (1) SYS.DBMS_DRS in the DataGuard component (DB03), (2) SYS.DBMS_STANDARD in the PL/SQL component (DB10), (3) MDSYS.RTREE_IDX in the Spatial component (DB16), and (4) SQL Compiler (DB17). NOTE: a reliable researcher claims that DB17 is for using Views to perform unauthorized insert, update, or delete actions.
Software vulnerabilities results 1 to 20 of 2573
Page:
1
2
3
4
5
...
129
►