CVE-2007-3278 affects PostgreSQL 8.1 and later versions when local trust authentication and the dblink library are enabled. This vulnerability allows remote attackers to access arbitrary accounts and execute SQL queries by manipulating the dblink host parameter to proxy connections through 127.0.0.1. With a CVSS score of 6.9, this vulnerability has a local attack vector, medium attack complexity, and high impact on confidentiality, integrity, and availability. There is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.3, < 7.3.21CPE matchmatch criteria | cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* | ||
>= 7.4, < 7.4.19CPE matchmatch criteria | cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* | ||
>= 8.0, < 8.0.15CPE matchmatch criteria | cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* | ||
>= 8.1, < 8.1.11CPE matchmatch criteria | cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* | ||
>= 8.2, < 8.2.6CPE matchmatch criteria | cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.