CVE-2006-2081
Last modified
CVE-2006-2081 is a vulnerability of currently unknown severity. Oracle Database Server 10g Release 2 allows local users to execute arbitrary SQL queries via the GET_DOMAIN_INDEX_METADATA function in the DBMS_EXPORT_EXTENSION package. NOTE: this issue was originally linked to DB05 (CVE-2006-1870), but a reliable third party has claimed that it is not the same issue. EPSS estimates a 21.56% chance of exploitation in the next 30 days.
Description
Oracle Database Server 10g Release 2 allows local users to execute arbitrary SQL queries via the GET_DOMAIN_INDEX_METADATA function in the DBMS_EXPORT_EXTENSION package. NOTE: this issue was originally linked to DB05 (CVE-2006-1870), but a reliable third party has claimed that it is not the same issue. Based on details of the problem, the primary issue appears to be insecure privileges that facilitate the introduction of SQL in a way that is not related to special characters, so this is not "SQL injection" per se.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Database Server | All versions |
References
- http://www.kb.cert.org/vuls/id/932124US Government Resource
- http://www.kb.cert.org/vuls/id/932124US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-2081?
How severe is CVE-2006-2081?
How do I fix CVE-2006-2081?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2006
- CVE-2006-2075Unspecified vulnerability in MyDNS 1.1.0 allows remote attac…
- CVE-2006-2076Memory leak in Paul Rombouts pdnsd before 1.2.4 allows remot…
- CVE-2006-2077Buffer overflow in Paul Rombouts pdnsd before 1.2.4 has unkn…
- CVE-2006-2078Multiple unspecified vulnerabilities in multiple FITELnet pr…
- CVE-2006-2079Cross-site scripting (XSS) vulnerability in portfolio.php in…
- CVE-2006-2080SQL injection vulnerability in portfolio_photo_popup.php in …
- CVE-2006-2082Directory traversal vulnerability in Quake 3 engine, as used…
- CVE-2006-2083Integer overflow in the receive_xattr function in the extend…
- CVE-2006-2084Multiple cross-site scripting (XSS) vulnerabilities in Farsi…
- CVE-2006-2085Multiple buffer overflows in (1) CxAce60.dll and (2) CxAce60…
- CVE-2006-2086Buffer overflow in JuniperSetupDLL.dll, loaded from JuniperS…
- CVE-2006-2087The Gmax Mail client in Hitachi Groupmax before 20060426 all…
Are you affected by CVE-2006-2081?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
