Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2007-3278
Description:PostgreSQL 8.1 and probably later versions, when local trust authentication is enabled and the Database Link library (dblink) is installed, allows remote attackers to access arbitrary accounts and execute arbitrary SQL queries via a dblink host parameter that proxies the connection from 127.0.0.1.
Test IDs: 1.3.6.1.4.1.25623.1.0.60178   1.3.6.1.4.1.25623.1.0.60180  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2007-3278
Bugtraq: 20070616 Having Fun With PostgreSQL (Google Search)
http://www.securityfocus.com/archive/1/471541/100/0/threaded
Bugtraq: 20070618 Re: Having Fun With PostgreSQL (Google Search)
http://www.securityfocus.com/archive/1/471644/100/0/threaded
Debian Security Information: DSA-1460 (Google Search)
http://www.debian.org/security/2008/dsa-1460
Debian Security Information: DSA-1463 (Google Search)
http://www.debian.org/security/2008/dsa-1463
http://security.gentoo.org/glsa/glsa-200801-15.xml
HPdes Security Advisory: HPSBTU02325
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01420154
HPdes Security Advisory: SSRT080006
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01420154
http://www.mandriva.com/security/advisories?name=MDKSA-2007:188
http://www.leidecker.info/pgshell/Having_Fun_With_PostgreSQL.txt
http://www.portcullis.co.uk/uplds/whitepapers/Having_Fun_With_PostgreSQL.pdf
http://osvdb.org/40899
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10334
RedHat Security Advisories: RHSA-2008:0038
http://www.redhat.com/support/errata/RHSA-2008-0038.html
RedHat Security Advisories: RHSA-2008:0039
http://www.redhat.com/support/errata/RHSA-2008-0039.html
RedHat Security Advisories: RHSA-2008:0040
http://www.redhat.com/support/errata/RHSA-2008-0040.html
http://secunia.com/advisories/28376
http://secunia.com/advisories/28437
http://secunia.com/advisories/28438
http://secunia.com/advisories/28445
http://secunia.com/advisories/28454
http://secunia.com/advisories/28477
http://secunia.com/advisories/28479
http://secunia.com/advisories/28679
http://secunia.com/advisories/29638
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103197-1
http://sunsolve.sun.com/search/document.do?assetkey=1-66-200559-1
https://usn.ubuntu.com/568-1/
http://www.vupen.com/english/advisories/2008/0109
http://www.vupen.com/english/advisories/2008/1071/references
XForce ISS Database: postgresql-dblink-sql-injection(35142)
https://exchange.xforce.ibmcloud.com/vulnerabilities/35142




© 1998-2025 E-Soft Inc. All rights reserved.