SQL injection vulnerability in the query.xsql sample page in Oracle 9i Application Server (9iAS) allows remote attackers to execute arbitrary code via the sql parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Application_server | Oracle | 1.0.2 (including) | 1.0.2 (including) |
Application_server | Oracle | 1.0.2.1s (including) | 1.0.2.1s (including) |
Application_server | Oracle | 1.0.2.2 (including) | 1.0.2.2 (including) |
Application_server | Oracle | 9.0.2.0.0 (including) | 9.0.2.0.0 (including) |
Application_server | Oracle | 9.0.2.0.1 (including) | 9.0.2.0.1 (including) |