>> HP Oracle for Openview Multiple SQL Injection and Security Bypass Vulnerabilities
Title : HP Oracle for Openview Multiple SQL Injection and Security Bypass Vulnerabilities VUPEN ID : VUPEN/ADV-2006-1571 CVE ID : GENERIC-MAP-NOMATCH
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-04-28
Technical Description
Multiple vulnerabilities have been identified in Oracle for Openview (OfO). These flaws, initially reported in Oracle Critical Patch Update (April 2006), could be exploited by remote or local attackers to cause a denial of service, execute arbitrary commands, read and overwrite arbitrary files, disclose sensitive information, conduct SQL injection attacks, or bypass certain security restrictions. For additional information, see : VUPEN/ADV-2006-1397