← back
CVE-2007-5508

CVE-2007-5508

23Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 5.2%
from disclosure to weapon6 days
Published on NVDOct 17
1st PoC+6d
exploitation probability
5.2%top 8% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Multiple SQL injection vulnerabilities in the CTXSYS Intermedia application for the Oracle Text component (CTX_DOC) in Oracle Database 10.1.0.5 and 10.2.0.3 allow remote authenticated users to execute arbitrary SQL commands via the (1) THEMES, (2) GIST, (3) TOKENS, (4) FILTER, (5) HIGHLIGHT, and (6) MARKUP procedures, aka DB03. NOTE: remote unauthenticated attack vectors exist when CTXSYS is used with oracle Application Server.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.