Sploitus

CVE-2007-3278

1 known exploit for CVE-2007-3278

PostgreSQL 8.1 and probably later versions, when local trust authentication is enabled and the Database Link library (dblink) is installed, allows remote attackers to access arbitrary accounts and execute arbitrary SQL queries via a dblink host parameter that proxies the connection from 127.0.0.1.

Affected products
Postgresql, Red Hat
Postgresql
< 7.3.21, 7.4.19, 8.0.15, 8.1.11, 8.2.6
CVSS 2.0
6.9 MEDIUM
EPSS
1.3% (67th percentile)
Weakness
CWE-264
NVD status
Modified
Published
2007-06-19
CVE-2007-3278 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2007-3278

Proof-of-concept code and exploit modules indexed by Sploitus