CVE-2013-1899
Argument injection vulnerability in PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, and 9.0.x before 9.0.13 allows remote attackers to cause a denial of service (file corruption), and allows remote authenticated users to modify configuration settings and execute arbitrary code, via a connection request using a database name that begins with a "-" (hyphen).
- Affected products
- Postgresql, Suse, Libecpg6, Libpq5, Libpq5-32Bit, Libpq5-X86
- Postgresql
- = 9.2, 9.2.1, 9.2.2, 9.2.3
- CVSS 2.0
- 6.5 MEDIUM
- EPSS
- 54.3% (99th percentile)
- Weakness
- CWE-94
- NVD status
- Modified
- Published
- 2013-04-04
CVE-2013-1899 at NVD
3 known exploits for CVE-2013-1899
Proof-of-concept code and exploit modules indexed by Sploitus