CVE-2007-5511

Oracle Database Server - SQL Injection

Title source: rule

Description

SQL injection vulnerability in Workspace Manager for Oracle Database before OWM 10.2.0.4.1, OWM 10.1.0.8.0, and OWM 9.2.0.8.0 allows attackers to execute arbitrary SQL commands via the FINDRICSET procedure in the LT package. NOTE: this is probably covered by CVE-2007-5510, but there are insufficient details to be certain.

Exploits (4)

exploitdb WORKING POC VERIFIED
by bunker · perllocalmultiple
https://www.exploit-db.com/exploits/4571
exploitdb WORKING POC VERIFIED
by bunker · perllocalmultiple
https://www.exploit-db.com/exploits/4570
exploitdb WORKING POC VERIFIED
by sh2kerr · textlocalmultiple
https://www.exploit-db.com/exploits/4572
metasploit WORKING POC
by CG · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/sqli/oracle/lt_findricset_cursor.rb

Scores

EPSS 0.6562
EPSS Percentile 98.5%

Details

CWE
CWE-89
Status published
Products (1)
oracle/database_server
Published Oct 17, 2007
Tracked Since Feb 18, 2026