CVE-2004-1339

Oracle Database Server - SQL Injection via MDSYS.SDO_GEOM_TRIG_INS1 or MDSYS.SDO_LRS_TRIG_INS Triggers

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in the (1) MDSYS.SDO_GEOM_TRIG_INS1 and (2) MDSYS.SDO_LRS_TRIG_INS default triggers in Oracle 9i and 10g allows remote attackers to execute arbitrary SQL commands via the new.table_name or new.column_name parameters.

References (3)

Core 3
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=110382230614420&w=2
Patch, Vendor Advisory x_refsource_misc
http://www.ngssoftware.com/advisories/oracle23122004I.txt
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/18655

Scores

EPSS 0.0148
EPSS Percentile 71.3%

Details

CWE
CWE-89
Status published
Products (14)
oracle/database_server 10.2.1 r2
oracle/oracle9i 9.0
oracle/oracle9i 9.0.1
oracle/oracle9i 9.0.1.2
oracle/oracle9i 9.0.1.3
oracle/oracle9i 9.0.1.4
oracle/oracle9i 9.0.2
oracle/oracle9i 9.0.2.0.0
oracle/oracle9i 9.0.2.0.1
oracle/oracle9i 9.0.2.1
... and 4 more
Published Dec 23, 2004
Tracked Since Feb 18, 2026