peter bassill · operator
$ cve CVE-2007-5508 JSON

CVE-2007-5508 EXPLOIT

6.5
MEDIUM · CVSS 2.0 · EPSS 5.2% (pctl 92)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in the CTXSYS Intermedia application for the Oracle Text component (CTX_DOC) in Oracle Database 10.1.0.5 and 10.2.0.3 allow remote authenticated users to execute arbitrary SQL commands via the (1) THEMES, (2) GIST, (3) TOKENS, (4) FILTER, (5) HIGHLIGHT, and (6) MARKUP procedures, aka DB03. NOTE: remote unauthenticated attack vectors exist when CTXSYS is used with oracle Application Server.

Scoring

CVSS6.5 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS5.16% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2007-10-17
Last modified2026-06-16

Affected (1)

VendorProduct
oracledatabase server

Public exploits

SourceTitleDate
exploit-dbOracle 10g - 'CTX_DOC.MARKUP' SQL Injection2007-10-23

References

→ the Explorer  ·  watch your stack  ·  NVD