CVE-2004-1339

CWE-89SQL Injection3 documents3 sources
Severity
6.5MEDIUM
EPSS
0.5%
top 34.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 23
Latest updateApr 29

Description

SQL injection vulnerability in the (1) MDSYS.SDO_GEOM_TRIG_INS1 and (2) MDSYS.SDO_LRS_TRIG_INS default triggers in Oracle 9i and 10g allows remote attackers to execute arbitrary SQL commands via the new.table_name or new.column_name parameters.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 8.0 | Impact: 6.4

Affected Packages2 packages

NVDoracle/oracle9i13 versions+12

Patches

🔴Vulnerability Details

2
GHSA
GHSA-7v5p-vcr4-vrxf: SQL injection vulnerability in the (1) MDSYS2022-04-29
CVEList
CVE-2004-1339: SQL injection vulnerability in the (1) MDSYS2005-01-06