cbcvebase.
CVE-2007-3278
published 2007-06-19

CVE-2007-3278: PostgreSQL 8.1 and probably later versions, when local trust authentication is enabled and the Database Link library (dblink) is installed, allows remote…

PriorityP433medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
1.26%
66.2th percentile
PostgreSQL 8.1 and probably later versions, when local trust authentication is enabled and the Database Link library (dblink) is installed, allows remote attackers to access arbitrary accounts and execute arbitrary SQL queries via a dblink host parameter that proxies the connection from 127.0.0.1.

Affected

15 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
fedoraprojectfedora
fedoraprojectfedora
postgresqlpostgresql
postgresqlpostgresql>= 7.3 < 7.3.217.3.21
postgresqlpostgresql>= 7.3.0 < 7.3.217.3.21
postgresqlpostgresql>= 7.4 < 7.4.197.4.19
postgresqlpostgresql>= 7.4.0 < 7.4.197.4.19
postgresqlpostgresql>= 8.0 < 8.0.158.0.15
postgresqlpostgresql>= 8.0.0 < 8.0.158.0.15
postgresqlpostgresql>= 8.1 < 8.1.118.1.11
postgresqlpostgresql>= 8.1.0 < 8.1.118.1.11
postgresqlpostgresql>= 8.2 < 8.2.68.2.6
postgresqlpostgresql>= 8.2.0 < 8.2.68.2.6

CVSS provenance

nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat6.9MEDIUM
vendor_ubuntu6.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.