NVD
- Id
- 60571
- Name
- CVE-2006-1866
- Description
- Multiple unspecified vulnerabilities in Oracle Database Server 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, and other versions have unknown impact and attack vectors in the (1) Advanced Replication component, as identified by Vuln# DB01, and (2) Oracle Spatial component, as identified by Vuln# DB10. NOTE: details are unavailable from Oracle, but as of 20060421, they have not publicly disputed a claim by a reliable independent researcher that states that DB01 is an unknown issue in the DBMS_REPUTIL package, and DB10 is SQL injection in the INSERT_CATALOG, UPDATE_CATALOG, and DELETE_CATALOG functions of the SDO_CATALOG package.
- Reject
- CVSS Version
- 2
- CVSS Score
- 9.7
- Severity
- High
- CVSS Base Score
- 9.7
- CVSS Impact Subscore
- 9.5
- CVSS Exploit Subscore
- 10
- CVSS Vector
- (AV:N/AC:L/Au:N/C:P/I:C/A:C)
- Pub Date
- 2016-12-20
- Published
- 2006-04-20
- Modified Date
- 2012-10-22
- Seq
- 2006-1866