CVE Vulnerabilities

CVE-2002-1631

Published: Dec 31, 2002 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

SQL injection vulnerability in the query.xsql sample page in Oracle 9i Application Server (9iAS) allows remote attackers to execute arbitrary code via the sql parameter.

Affected Software

NameVendorStart VersionEnd Version
Application_serverOracle1.0.2 (including)1.0.2 (including)
Application_serverOracle1.0.2.1s (including)1.0.2.1s (including)
Application_serverOracle1.0.2.2 (including)1.0.2.2 (including)
Application_serverOracle9.0.2.0.0 (including)9.0.2.0.0 (including)
Application_serverOracle9.0.2.0.1 (including)9.0.2.0.1 (including)

References