支持本站 — 捐款将帮助我们持续运营

目标: 1000 元,已筹: 1000

100.0%
获取后续新漏洞提醒登录后订阅
一、 漏洞 CVE-2023-39417 基础信息
漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Postgresql: extension script @substitutions@ within quoting allow sql injection
来源: 美国国家漏洞数据库 NVD
Vulnerability Description
IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). If an administrator has installed files of a vulnerable, trusted, non-bundled extension, an attacker with database-level CREATE privilege can execute arbitrary code as the bootstrap superuser.
来源: 美国国家漏洞数据库 NVD
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
来源: 美国国家漏洞数据库 NVD
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
来源: 美国国家漏洞数据库 NVD
Vulnerability Title
PostgreSQL SQL注入漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
PostgreSQL是PostgreSQL组织的一套自由的对象关系型数据库管理系统。该系统支持大部分SQL标准并且提供了许多其他特性,例如外键、触发器、视图等。 PostgreSQL 存在安全漏洞。攻击者利用该漏洞可以执行任意代码。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD
受影响产品
厂商产品影响版本CPE订阅
Red HatRed Hat Advanced Cluster Security 4.2 4.2.4-6 ~ * cpe:/a:redhat:advanced_cluster_security:4.2::el8
Red HatRed Hat Advanced Cluster Security 4.2 4.2.4-6 ~ * cpe:/a:redhat:advanced_cluster_security:4.2::el8
Red HatRed Hat Advanced Cluster Security 4.2 4.2.4-7 ~ * cpe:/a:redhat:advanced_cluster_security:4.2::el8
Red HatRed Hat Advanced Cluster Security 4.2 4.2.4-6 ~ * cpe:/a:redhat:advanced_cluster_security:4.2::el8
Red HatRed Hat Advanced Cluster Security 4.2 4.2.4-7 ~ * cpe:/a:redhat:advanced_cluster_security:4.2::el8
Red HatRed Hat Enterprise Linux 8 8090020231114113712.a75119d5 ~ * cpe:/a:redhat:enterprise_linux:8::appstream
Red HatRed Hat Enterprise Linux 8 8090020231128173330.a75119d5 ~ * cpe:/a:redhat:enterprise_linux:8::appstream
Red HatRed Hat Enterprise Linux 8 8090020231114113548.a75119d5 ~ * cpe:/a:redhat:enterprise_linux:8::appstream
Red HatRed Hat Enterprise Linux 8.2 Advanced Update Support 8020020231128165246.4cda2c84 ~ * cpe:/a:redhat:rhel_tus:8.2::appstream
Red HatRed Hat Enterprise Linux 8.2 Telecommunications Update Service 8020020231128165246.4cda2c84 ~ * cpe:/a:redhat:rhel_tus:8.2::appstream
Red HatRed Hat Enterprise Linux 8.2 Update Services for SAP Solutions 8020020231128165246.4cda2c84 ~ * cpe:/a:redhat:rhel_tus:8.2::appstream
Red HatRed Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support 8040020231127153301.522a0ee4 ~ * cpe:/a:redhat:rhel_tus:8.4::appstream
Red HatRed Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support 8040020231127154806.522a0ee4 ~ * cpe:/a:redhat:rhel_tus:8.4::appstream
Red HatRed Hat Enterprise Linux 8.4 Telecommunications Update Service 8040020231127153301.522a0ee4 ~ * cpe:/a:redhat:rhel_tus:8.4::appstream
Red HatRed Hat Enterprise Linux 8.4 Telecommunications Update Service 8040020231127154806.522a0ee4 ~ * cpe:/a:redhat:rhel_tus:8.4::appstream
Red HatRed Hat Enterprise Linux 8.4 Update Services for SAP Solutions 8040020231127153301.522a0ee4 ~ * cpe:/a:redhat:rhel_tus:8.4::appstream
Red HatRed Hat Enterprise Linux 8.4 Update Services for SAP Solutions 8040020231127154806.522a0ee4 ~ * cpe:/a:redhat:rhel_tus:8.4::appstream
Red HatRed Hat Enterprise Linux 8.6 Extended Update Support 8060020231114115246.ad008a3a ~ * cpe:/a:redhat:rhel_eus:8.6::appstream
Red HatRed Hat Enterprise Linux 8.6 Extended Update Support 8060020231128165328.ad008a3a ~ * cpe:/a:redhat:rhel_eus:8.6::appstream
Red HatRed Hat Enterprise Linux 8.8 Extended Update Support 8080020231114105206.63b34585 ~ * cpe:/a:redhat:rhel_eus:8.8::appstream
Red HatRed Hat Enterprise Linux 8.8 Extended Update Support 8080020231128165335.63b34585 ~ * cpe:/a:redhat:rhel_eus:8.8::appstream
Red HatRed Hat Enterprise Linux 8.8 Extended Update Support 8080020231113134015.63b34585 ~ * cpe:/a:redhat:rhel_eus:8.8::appstream
Red HatRed Hat Enterprise Linux 9 0:13.13-1.el9_3 ~ * cpe:/a:redhat:enterprise_linux:9::crb
Red HatRed Hat Enterprise Linux 9 9030020231120082734.rhel9 ~ * cpe:/a:redhat:enterprise_linux:9::appstream
Red HatRed Hat Enterprise Linux 9.0 Extended Update Support 0:13.13-1.el9_0 ~ * cpe:/a:redhat:rhel_eus:9.0::appstream
Red HatRed Hat Enterprise Linux 9.2 Extended Update Support 0:13.13-1.el9_2 ~ * cpe:/a:redhat:rhel_eus:9.2::appstream
Red HatRed Hat Enterprise Linux 9.2 Extended Update Support 9020020231115020618.rhel9 ~ * cpe:/a:redhat:rhel_eus:9.2::appstream
Red HatRed Hat Software Collections for Red Hat Enterprise Linux 7 0:12.17-1.el7 ~ * cpe:/a:redhat:rhel_software_collections:3::el7
Red HatRed Hat Software Collections for Red Hat Enterprise Linux 7 0:13.13-1.el7 ~ * cpe:/a:redhat:rhel_software_collections:3::el7
Red HatRHACS-3.74-RHEL-8 3.74.8-9 ~ * cpe:/a:redhat:advanced_cluster_security:3.74::el8
Red HatRHACS-3.74-RHEL-8 3.74.8-9 ~ * cpe:/a:redhat:advanced_cluster_security:3.74::el8
Red HatRHACS-3.74-RHEL-8 3.74.8-7 ~ * cpe:/a:redhat:advanced_cluster_security:3.74::el8
Red HatRHACS-3.74-RHEL-8 3.74.8-9 ~ * cpe:/a:redhat:advanced_cluster_security:3.74::el8
Red HatRHACS-3.74-RHEL-8 3.74.8-9 ~ * cpe:/a:redhat:advanced_cluster_security:3.74::el8
Red HatRHACS-4.1-RHEL-8 4.1.6-6 ~ * cpe:/a:redhat:advanced_cluster_security:4.1::el8
Red HatRHACS-4.1-RHEL-8 4.1.6-6 ~ * cpe:/a:redhat:advanced_cluster_security:4.1::el8
Red HatRHACS-4.1-RHEL-8 4.1.6-6 ~ * cpe:/a:redhat:advanced_cluster_security:4.1::el8
Red HatRHACS-4.1-RHEL-8 4.1.6-6 ~ * cpe:/a:redhat:advanced_cluster_security:4.1::el8
Red HatRHACS-4.1-RHEL-8 4.1.6-6 ~ * cpe:/a:redhat:advanced_cluster_security:4.1::el8
Red HatRed Hat Enterprise Linux 6-cpe:/o:redhat:enterprise_linux:6
Red HatRed Hat Enterprise Linux 7-cpe:/o:redhat:enterprise_linux:7
Red HatRed Hat Enterprise Linux 8-cpe:/o:redhat:enterprise_linux:8
Red HatRed Hat Software Collections-cpe:/a:redhat:rhel_software_collections:3
二、漏洞 CVE-2023-39417 的公开POC
#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC
三、漏洞 CVE-2023-39417 的情报信息
Please 登录 to view more intelligence information
四、漏洞 CVE-2023-39417 的评论

暂无评论


发表评论