CVE-2006-7138
Title: Oracle Apex Injection (SQLi/OSi)
Proof Of Concept
No public PoC currently indexed for CVE-2006-7138.
Vulnerability Summary
CVE-2006-7138: SQL injection vulnerability in wwv_flow_utilities.gen_popup_list in the WWV_FLOW_UTILITIES package for Oracle APEX/HTMLDB before 2.2 allows remote authenticated users to execute arbitrary SQL by modifying the P_LOV parameter and calculating a matching MD5 checksum for the P_LOV_CHECKSUM parameter. NOTE: it is likely that this issue is subsumed by CVE-2006-5351, but due to lack of details from Oracle, this cannot be proven.
Impacted Vendors
Reference Links
AV:N/AC:M/Au:S/C:P/I:P/A:P
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
CVE-2006-7138 Exploits & PoCs (Proof Of Concept)
No public PoCs found in our database for this CVE.
Vulnerability data or affected products updated.
Vulnerability first announced in NVD.
Attack Vector Matrix
AV:N/AC:M/Au:S/C:P/I:P/A:P
Affected Stack
No specific products linked.