CVE-2004-1339
Oracle Database Server - SQL Injection via MDSYS.SDO_GEOM_TRIG_INS1 or MDSYS.SDO_LRS_TRIG_INS Triggers
Title source: llmDescription
SQL injection vulnerability in the (1) MDSYS.SDO_GEOM_TRIG_INS1 and (2) MDSYS.SDO_LRS_TRIG_INS default triggers in Oracle 9i and 10g allows remote attackers to execute arbitrary SQL commands via the new.table_name or new.column_name parameters.
References (3)
Core 3
Core References
Mailing List mailing-list
x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=110382230614420&w=2
Patch, Vendor Advisory x_refsource_misc
http://www.ngssoftware.com/advisories/oracle23122004I.txt
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/18655
Scores
EPSS
0.0148
EPSS Percentile
71.3%
Details
CWE
CWE-89
Status
published
Products (14)
oracle/database_server
10.2.1 r2
oracle/oracle9i
9.0
oracle/oracle9i
9.0.1
oracle/oracle9i
9.0.1.2
oracle/oracle9i
9.0.1.3
oracle/oracle9i
9.0.1.4
oracle/oracle9i
9.0.2
oracle/oracle9i
9.0.2.0.0
oracle/oracle9i
9.0.2.0.1
oracle/oracle9i
9.0.2.1
... and 4 more
Published
Dec 23, 2004
Tracked Since
Feb 18, 2026