CVE-2007-3280

PostgreSQL 8.1 - RCE

Title source: llm

Description

The Database Link library (dblink) in PostgreSQL 8.1 implements functions via CREATE statements that map to arbitrary libraries based on the C programming language, which allows remote authenticated superusers to map and execute a function from any library, as demonstrated by using the system function in libc.so.6 to gain shell access.

Exploits (2)

nomisec WRITEUP
by denuwanjayasekara · poc
https://github.com/denuwanjayasekara/CVE-Exploitation-Reports
metasploit WORKING POC EXCELLENT
by midnitesnake, egypt, todb, lucipher · rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/postgres/postgres_payload.rb

Scores

EPSS 0.4892
EPSS Percentile 97.7%

Classification

Status draft

Affected Products (1)

postgresql/postgresql

Timeline

Published Jun 19, 2007
Tracked Since Feb 18, 2026