VYPR
Unrated severityNVD Advisory· Published Jun 19, 2007· Updated Jun 16, 2026

CVE-2007-3278

CVE-2007-3278

Description

PostgreSQL 8.1 and probably later versions, when local trust authentication is enabled and the Database Link library (dblink) is installed, allows remote attackers to access arbitrary accounts and execute arbitrary SQL queries via a dblink host parameter that proxies the connection from 127.0.0.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*range: >=7.3,<7.3.21
    • (no CPE)range: >=8.1
  • Debian/linux2 versions
    cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

29

News mentions

0

No linked articles in our index yet.