 |
|
|
|
Oracle SQL injection lateral attacks updated since 27.04.2008 | | Published: |  | 19.07.2008 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 8951 | | Type: |  | library | | Level: |  | 5/10 | | Description: |  | SQL injection into uncontrolled PL/SQL procedires is possible with e.g. modification of data format with ALTER SESSION. |
| Original document |  | David Litchfield, Lateral SQL Injection Revisited - No Special Privs Required (19.07.2008) |
| |  | David Litchfield, A New Class of Vulnerability in Oracle: Lateral SQL Injection (27.04.2008) |
| Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl) | | Published: |  | 19.07.2008 | | Source: |  | | | SecurityVulns ID: |  | 9159 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc.
Contrexx CMS: crossite scripting, registration automation. |
| |
|
| |