Oracle Retail Central Office CVE-2013-2397 SQL Injection Vulnerability
BID:59156
Info
Oracle Retail Central Office CVE-2013-2397 SQL Injection Vulnerability
| Bugtraq ID: | 59156 |
| Class: | Unknown |
| CVE: |
CVE-2013-2397 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 16 2013 12:00AM |
| Updated: | May 02 2013 07:11PM |
| Credit: | Andrew Davies of NCC Group |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Oracle Retail Central Office CVE-2013-2397 SQL Injection Vulnerability
Oracle Retail Central Office is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
This vulnerability affects the following supported versions:
13.1, 13.2, 13.3, 13.4
Oracle Retail Central Office is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
This vulnerability affects the following supported versions:
13.1, 13.2, 13.3, 13.4
Exploit / POC
Oracle Retail Central Office CVE-2013-2397 Remote Security Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Oracle Retail Central Office CVE-2013-2397 SQL Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Oracle Retail Central Office CVE-2013-2397 SQL Injection Vulnerability
References:
References: