CVE-2019-9193
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute arbitrary code in the context of the database's operating system user. This functionality is enabled by default and can be abused to run arbitrary operating system commands on Windows, Linux, and macOS. NOTE: Third parties claim/state this is not an issue because PostgreSQL functionality for ‘COPY TO/FROM PROGRAM’ is acting as intended. References state that in PostgreSQL, a superuser can execute commands as the server user without using the ‘COPY FROM PROGRAM’.
- Affected products
- Alt Linux, Postgresql
- Postgresql
- ≤ 11.2
- Fix
- Available
- CVSS 2.0
- 9.0 HIGH
- CVSS 3.1
- 7.2 HIGH
- EPSS
- 91.7% (100th percentile)
- Weakness
- CWE-78
- NVD status
- Modified
- Published
- 2019-04-01
CVE-2019-9193 at NVD
16 known exploits for CVE-2019-9193
Proof-of-concept code and exploit modules indexed by Sploitus
SQLi
Exploit for OS Command Injection in Postgresql
Exploit for OS Command Injection in Postgresql
Exploit for OS Command Injection in Postgresql
Exploit for OS Command Injection in Postgresql
PostgreSQL 9.6.1 Remote Code Execution
PostgreSQL 9.6.1 - Remote Code Execution (RCE) (Authenticated)
PostgreSQL 9.6.1 - Remote Code Execution (Authenticated) Exploit
PostgreSQL 9.3-11.7 - Remote Code Execution (RCE) (Authenticated)
PostgreSQL 11.7 Remote Code Execution
PostgreSQL 9.3-11.7 - Remote Code Execution (Authenticated) Exploit
Exploit for OS Command Injection in Postgresql
PostgreSQL 9.3 - COPY FROM PROGRAM Command Execution (Metasploit)
PostgreSQL COPY FROM PROGRAM Command Execution
PostgreSQL COPY FROM PROGRAM Command Execution Exploit
PostgreSQL COPY FROM PROGRAM Command Execution