PT-2005-4019 · Oracle · Oracle9I Database Server
Alexander Kornbrust
·
Published
2005-10-14
·
Updated
2017-07-11
·
CVE-2005-3205
CVSS v2.0
3.5
Low
| Vector | AV:N/AC:M/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Oracle9i Database Server Release 2 version 9.0.2.4
Description
A cross-site scripting issue exists, allowing remote attackers to inject arbitrary web script or HTML. This occurs via script in the
set markup HTML TABLE command, which is executed when the user selects a table.Recommendations
For Oracle9i Database Server Release 2 version 9.0.2.4, consider restricting the use of the "set markup HTML TABLE" command to minimize the risk of exploitation. Avoid using this command until a fix is available. At the moment, there is no information about a newer version that contains a fix for this issue.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oracle9I Database Server