CVE-2005-2983

Oracle Reports - SQL Injection via Lexical References Parameter Form

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in Oracle Reports that use Lexical References allows remote attackers to execute arbitrary SQL commands via the values in the parameter form that appears when the paramform parameter is set to yes.

References (3)

Core 3
Core References
Exploit, Vendor Advisory mailing-list x_refsource_fulldisc
http://lists.grok.org.uk/pipermail/full-disclosure/2005-September/037156.html
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=112681849113948&w=2

Scores

EPSS 0.0218
EPSS Percentile 80.5%

Details

CWE
CWE-89
Status published
Products (1)
oracle/reports 1.00
Published Sep 20, 2005
Tracked Since Feb 18, 2026