漏洞信息详情
PostgreSQL JDBC驱动程序设计错误漏洞
- CNNVD编号:CNNVD-201210-052
- 危害等级: 高危
![图片[1]-PostgreSQL JDBC驱动程序设计错误漏洞-一一网](https://www.proyy.com/skycj/data/images/2021-08-18/bbdd3e8868c10d22861b2275d65f4500.png)
- CVE编号:
CVE-2012-1618
- 漏洞类型:
设计错误
- 发布时间:
2012-10-11
- 威胁类型:
远程
- 更新时间:
2012-10-11
- 厂 商:
postgresql - 漏洞来源:
-
漏洞简介
PostgreSQL JDBC driver是一个数据库驱动程序。
PostgreSQL JDBC驱动程序8.2之前版本中存在交互错误漏洞。当使用带有PostgreSQL服务器的‘standard_conforming_strings’选项启用时,如默认配置的PostgreSQL 9.1版本,没有正确的释放未指定的JDBC语句参数。远程攻击者可利用该漏洞进行SQL注入攻击。
参考网址
来源: bugzilla.novell.com
链接:https://bugzilla.novell.com/show_bug.cgi?id=754273
来源: OSVDB
名称: 80641
来源: MLIST
名称: [oss-security] 20120404 Re: CVE DISPUTE notification: postgresql-jdbc: SQL injection due improper escaping of JDBC statement parameters
链接:http://www.openwall.com/lists/oss-security/2012/04/04/9
来源: MLIST
名称: [oss-security] 20120404 Re: Re: [JDBC] CVE DISPUTE notification: postgresql-jdbc: SQL injection due improper escaping of JDBC statement parameters
链接:http://www.openwall.com/lists/oss-security/2012/04/04/5
来源: MLIST
名称: [oss-security] 20120404 Re: Re: [pgsql-security] postgresql-jdbc 8.1 SQL injection with postgresql server 9.1
链接:http://www.openwall.com/lists/oss-security/2012/04/04/4
来源: MLIST
名称: [oss-security] 20120404 Re: CVE DISPUTE notification: postgresql-jdbc: SQL injection due improper escaping of JDBC statement parameters
链接:http://www.openwall.com/lists/oss-security/2012/04/04/11
来源: MLIST
名称: [oss-security] 20120402 Re: [JDBC] CVE DISPUTE notification: postgresql-jdbc: SQL injection due improper escaping of JDBC statement parameters
链接:http://www.openwall.com/lists/oss-security/2012/04/02/4
来源: MLIST
名称: [oss-security] 20120331 SQL injection attack possible when connecting to PostgreSQL 9.1 with version 8.1 JDBC driver
链接:http://www.openwall.com/lists/oss-security/2012/03/31/1
来源: MLIST
名称: [oss-security] 20120330 postgresql-jdbc 8.1 SQL injection with postgresql server 9.1
链接:http://www.openwall.com/lists/oss-security/2012/03/30/9
来源: MLIST
名称: [oss-security] 20120330 CVE DISPUTE notification: postgresql-jdbc: SQL injection due improper escaping of JDBC statement parameters
链接:http://www.openwall.com/lists/oss-security/2012/03/30/8
来源: MLIST
名称: [opensuse-security] 20120325 SQL injection attack possible when connecting to PostgreSQL 9.1 with version 8.1 JDBC driver
链接:http://lists.opensuse.org/opensuse-security/2012-03/msg00024.html
来源: BUGTRAQ
名称: 20120325 SQL injection attack possible when connecting to PostgreSQL 9.1 with version 8.1 JDBC driver
链接:http://archives.neohapsis.com/archives/bugtraq/2012-03/0126.html
来源:NSFOCUS
名称:20948
链接:http://www.nsfocus.net/vulndb/20948





















![[桜井宁宁]COS和泉纱雾超可爱写真福利集-一一网](https://www.proyy.com/skycj/data/images/2020-12-13/4d3cf227a85d7e79f5d6b4efb6bde3e8.jpg)

![[桜井宁宁] 爆乳奶牛少女cos写真-一一网](https://www.proyy.com/skycj/data/images/2020-12-13/d40483e126fcf567894e89c65eaca655.jpg)