Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-3860

Опубликовано: 18 июл. 2007
Источник: nvd
CVSS2: 7.5
EPSS Низкий

Описание

Unspecified vulnerability in Oracle Application Express (formerly Oracle HTML DB) 2.2.0.00.32 up to 3.0.0.00.20 allows developers to have an unknown impact via unknown attack vectors, aka APEX01. NOTE: a reliable researcher states that this is SQL injection in the wwv_flow_security.check_db_password function due to insufficient checks for '"' characters.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:oracle:apex:*:*:*:*:*:*:*:*
Версия до 3.0.0.00.20 (включая)
cpe:2.3:a:oracle:apex:2.2.0.00.32:*:*:*:*:*:*:*

EPSS

Процентиль: 82%
0.01689
Низкий

7.5 High

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

Unspecified vulnerability in Oracle Application Express (formerly Oracle HTML DB) 2.2.0.00.32 up to 3.0.0.00.20 allows developers to have an unknown impact via unknown attack vectors, aka APEX01. NOTE: a reliable researcher states that this is SQL injection in the wwv_flow_security.check_db_password function due to insufficient checks for '"' characters.

EPSS

Процентиль: 82%
0.01689
Низкий

7.5 High

CVSS2

Дефекты

NVD-CWE-Other