Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2007-3860

Unspecified vulnerability in Oracle Application Express (formerly Oracle HTML DB) 2.2.0.00.32 up to 3.0.0.00.20 allows developers to have an unknown impact via unknown attack vectors, aka APEX01. NOTE: a reliable researcher states that this is SQL injection in the wwv_flow_security.check_db_password function due to insufficient checks for '"' characters.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.014
EPSS Ranking 79.3%
CVSS Severity
CVSS v2 Score 7.5
References
Products affected by CVE-2007-3860
  • Oracle » Apex » Version: N/A
    cpe:2.3:a:oracle:apex:-
  • Oracle » Apex » Version: 2.0
    cpe:2.3:a:oracle:apex:2.0
  • Oracle » Apex » Version: 2.1
    cpe:2.3:a:oracle:apex:2.1
  • Oracle » Apex » Version: 2.2
    cpe:2.3:a:oracle:apex:2.2
  • Oracle » Apex » Version: 2.2.0.00.32
    cpe:2.3:a:oracle:apex:2.2.0.00.32
  • Oracle » Apex » Version: 3.0.0.00.20
    cpe:2.3:a:oracle:apex:3.0.0.00.20


Contact Us

Shodan ® - All rights reserved