CVE-2005-2983
Oracle Reports - SQL Injection via Lexical References Parameter Form
Title source: llmDescription
SQL injection vulnerability in Oracle Reports that use Lexical References allows remote attackers to execute arbitrary SQL commands via the values in the parameter form that appears when the paramform parameter is set to yes.
References (3)
Core 3
Core References
Exploit, Vendor Advisory mailing-list
x_refsource_fulldisc
http://lists.grok.org.uk/pipermail/full-disclosure/2005-September/037156.html
Mailing List mailing-list
x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=112681849113948&w=2
Exploit, Vendor Advisory x_refsource_misc
http://www.red-database-security.com/wp/sql_injection_reports_us.pdf
Scores
EPSS
0.0218
EPSS Percentile
80.5%
Details
CWE
CWE-89
Status
published
Products (1)
oracle/reports
1.00
Published
Sep 20, 2005
Tracked Since
Feb 18, 2026