Oracle FAQ | Your Portal to the Oracle Knowledge Grid |
![]() |
![]() |
Home -> Community -> Mailing Lists -> Oracle-L -> Re: FW: [VulnWatch] Multiple high risk vulnerabilities in Oracle RDBMS 10g/9i
i was under the impression(apparently wrong) that if you use bind variables, sql injection wont work. the only way i know to get sql injection to work is to dummy up the quotes to manipulate the where clause?
-------------- Original message --------------
> Hi Ruth,
>
> This is related to the first quarterly patch set release. NGS are
> probably one of many researchers who have found security bugs that
-- http://www.freelists.org/webpage/oracle-lReceived on Wed Jan 19 2005 - 00:19:59 CST
![]() |
![]() |