漏洞描述 PostgreSQL是PostgreSQL组织的一套自由的对象关系型数据库管理系统。该系统支持大部分SQL标准并且提供了许多其他特性,例如外键、触发器、视图等。</br>PostgreSQL9.3及之前版本中的入导出数据命令‘COPY TO/FROMPROGRAM’存在操作系统命令注入漏洞。攻击者可利用该漏洞获取数据库超级用户权限,从而执行任意系统命令。
相关漏洞推荐 POC CVE-2019-9193: PostgreSQL 9.3-12.3 Authenticated Remote Code Execution POC log-connections-disabled: PostgreSQL "log_connections" Parameter - Disabled POC log-disconnections-disabled: PostgreSQL "log_disconnections" Parameter - Disabled POC log-duration-disabled: PostgreSQL "log_duration" Parameter - Disabled POC postgresql-audit-disabled: PostgreSQL Database Instances - SQL Auditing Disabled POC ec2-unrestricted-pgsql: Unrestricted PostgreSQL Access POC azure-postgresql-db-delete-unalerted: Azure PostgreSQL Database Delete Alert Not Configured POC azure-postgresql-db-update-unalerted: Azure PostgreSQL Database Create/Update Alert Not Configured POC azure-nsg-postgresql-unrestricted: Unrestricted PostgreSQL Database Access in Azure NSGs POC azure-postgres-allow-azure-services-disabled: Azure PostgreSQL Access From Azure Services Disabled POC azure-postgres-connection-throttling-disabled: Azure PostgreSQL Server Connection Throttling Disabled POC azure-postgres-log-checkpoints-disabled: Azure PostgreSQL Flexible Server log_checkpoints Disabled POC azure-postgres-log-connections-disabled: Azure PostgreSQL Log Connections Not Enabled