Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
CRLF injection vulnerability in pg_dump in PostgreSQL 8.3.x before 8.3.18, 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 allows user-assisted remote attackers to execute arbitrary SQL commands via a crafted file containing object names with newlines, which are inserted into an SQL script that is used when the database is restored.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PostgreSQL 安全漏洞
Vulnerability Description
PostgreSQL是一款高级对象关系型数据库管理系统,支持扩展的SQL标准子集。 PostgreSQL 8.3.18之前的8.3.x版本、8.4.11之前的8.4.x版本、9.0.7之前的9.0.x版本和9.1.3之前的9.1.x版本中存在CRLF注入漏洞,该漏洞源于当向评论中插入对象名称时pg_dump中的输入验证错误。攻击者可利用该漏洞借助回车符或向dump脚本中插入SQL命令,避免评论。
CVSS Information
N/A
Vulnerability Type
N/A