Unrated severityNVD Advisory· Published Dec 31, 2002· Updated Jun 16, 2026
CVE-2002-1631
CVE-2002-1631
Description
SQL injection vulnerability in the query.xsql sample page in Oracle 9i Application Server (9iAS) allows remote attackers to execute arbitrary code via the sql parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:oracle:application_server:1.0.2.1s:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:oracle:application_server:1.0.2.1s:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:application_server:1.0.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:application_server:1.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:application_server:9.0.2.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:application_server:9.0.2.0.1:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
5- www.kb.cert.org/vuls/id/717827nvdPatchUS Government Resource
- www.nextgenss.com/papers/hpoas.pdfnvdExploitPatch
- www.kb.cert.org/vuls/id/SVIM-576QLZnvdUS Government Resource
- www.oracle.com/technology/deploy/security/pdf/ias_modplsql_alert.pdfnvd
- www.securityfocus.com/bid/6556nvd
News mentions
0No linked articles in our index yet.