NVD
- Id
- 63941
- Name
- CVE-2006-5340
- Description
- Multiple unspecified vulnerabilities in Oracle Spatial component in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.2 have unknown impact and remote authenticated attack vectors related to (1) mdsys.sdo_lrs, aka Vuln# DB13, and (2) Vuln# DB17. NOTE: as of 20061023, Oracle has not disputed reports from reliable third parties that DB13 is related to bypassing input validation for SQL injection related to convert_to_lrs_layer and dbms_assert, and DB17 is related to SQL injection in the trigger in the SDO_DROP_USER package.
- Reject
- CVSS Version
- 2
- CVSS Score
- 7.1
- Severity
- High
- CVSS Base Score
- 7.1
- CVSS Impact Subscore
- 10
- CVSS Exploit Subscore
- 3.9
- CVSS Vector
- (AV:N/AC:H/Au:S/C:C/I:C/A:C)
- Pub Date
- 2016-12-20
- Published
- 2006-10-17
- Modified Date
- 2016-04-29
- Seq
- 2006-5340