Vulnerability Description
SQL injection vulnerability in the query.xsql sample page in Oracle 9i Application Server (9iAS) allows remote attackers to execute arbitrary code via the sql parameter.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Application Server | 1.0.2 |
References
- http://www.kb.cert.org/vuls/id/717827PatchUS Government Resource
- http://www.kb.cert.org/vuls/id/SVIM-576QLZUS Government Resource
- http://www.nextgenss.com/papers/hpoas.pdfExploitPatch
- http://www.oracle.com/technology/deploy/security/pdf/ias_modplsql_alert.pdf
- http://www.securityfocus.com/bid/6556
- http://www.kb.cert.org/vuls/id/717827PatchUS Government Resource
- http://www.kb.cert.org/vuls/id/SVIM-576QLZUS Government Resource
- http://www.nextgenss.com/papers/hpoas.pdfExploitPatch
- http://www.oracle.com/technology/deploy/security/pdf/ias_modplsql_alert.pdf
- http://www.securityfocus.com/bid/6556
FAQ
What is CVE-2002-1631?
CVE-2002-1631 is a vulnerability with a CVSS score of 7.5 (HIGH). SQL injection vulnerability in the query.xsql sample page in Oracle 9i Application Server (9iAS) allows remote attackers to execute arbitrary code via the sql parameter.
How severe is CVE-2002-1631?
CVE-2002-1631 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-1631?
Check the references section above for vendor advisories and patch information. Affected products include: Oracle Application Server.