By using specially crafted parameters (in double quotes) it is possible to bypass the input validation of the package dbms_assert and inject SQL code. This makes dozens of already fixed Oracle vulnerabilities exploitable in all versions of Oracle again (8.1.7.4 ¨C 10.2.0.2, fully patched with Oracle CPU July 2006). I informed Oracle about this problem end of April and informed Oracle about some bugs + exploits.