Back
CVE-2002-1631
SQL injection vulnerability in the query.xsql sample page in Oracle 9i Application Server (9iAS) allows remote attackers to execute arbitrary code via the sql parameter.
Published: Dec 31, 2002
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (5)
| Vendor | Product | Version |
|---|---|---|
| oracle | application_server | 1.0.2 |
| oracle | application_server | 1.0.2.1s |
| oracle | application_server | 1.0.2.2 |
| oracle | application_server | 9.0.2.0.0 |
| oracle | application_server | 9.0.2.0.1 |
GitHub Security Advisory GHSA-m54v-h5r2-5m3r
SQL injection vulnerability in the query.xsql sample page in Oracle 9i Application Server (9iAS)...
References (10)
- http://www.kb.cert.org/vuls/id/717827 Patch, US Government Resource
- http://www.kb.cert.org/vuls/id/SVIM-576QLZ US Government Resource
- http://www.nextgenss.com/papers/hpoas.pdf Exploit, Patch
- http://www.oracle.com/technology/deploy/security/pdf/ias_modplsql_alert.pdf
- http://www.securityfocus.com/bid/6556
- http://www.kb.cert.org/vuls/id/717827 Patch, US Government Resource
- http://www.kb.cert.org/vuls/id/SVIM-576QLZ US Government Resource
- http://www.nextgenss.com/papers/hpoas.pdf Exploit, Patch
- http://www.oracle.com/technology/deploy/security/pdf/ias_modplsql_alert.pdf
- http://www.securityfocus.com/bid/6556
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
7.67%
Top 6% most likely to be exploited
Threat Score
32.3 / 100
Data Sources
NVD
EPSS
GitHub