CVE-2013-1899
PostgreSQL Database Name Command Line Flag Injection
Title source: metasploitDescription
Argument injection vulnerability in PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, and 9.0.x before 9.0.13 allows remote attackers to cause a denial of service (file corruption), and allows remote authenticated users to modify configuration settings and execute arbitrary code, via a connection request using a database name that begins with a "-" (hyphen).
Exploits (1)
metasploit
SCANNER
by hdm · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/postgres/postgres_dbname_flag_injection.rb
References (18)
Scores
EPSS
0.8112
EPSS Percentile
99.2%
Details
CWE
CWE-94
Status
published
Products (31)
canonical/ubuntu_linux
8.04
canonical/ubuntu_linux
10.04
canonical/ubuntu_linux
11.10
canonical/ubuntu_linux
12.04
canonical/ubuntu_linux
12.10
postgresql/postgresql
9.2
postgresql/postgresql
9.2.1
postgresql/postgresql
9.2.2
postgresql/postgresql
9.2.3
postgresql/postgresql
9.1
... and 21 more
Published
Apr 04, 2013
Tracked Since
Feb 18, 2026