It has been reported that Oracle9i application server is prone to a SQL injection vulnerability that may allow a remote attacker to inject malicious SQL syntax into database queries through a URL. The cause of this problem is due to insufficient sanitization of user-supplied data. An attacker may be able to exploit this issue to influence SQL query logic. Successful exploitation may disclose sensitive information about the underlying database to an attacker, which may be used to launch further attacks against a vulnerable system.
It has been reported that Oracle9i application server is prone to a SQL injection vulnerability that may allow a remote attacker to inject malicious SQL syntax into database queries through a URL. The cause of this problem is due to insufficient sanitization of user-supplied data. An attacker may be able to exploit this issue to influence SQL query logic. Successful exploitation may disclose sensitive information about the underlying database to an attacker, which may be used to launch further attacks against a vulnerable system.