Логотип exploitDog
bind:CVE-2012-3488
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2012-3488

Количество 7

Количество 7

ubuntu логотип

CVE-2012-3488

почти 13 лет назад

The libxslt support in contrib/xml2 in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 does not properly restrict access to files and URLs, which allows remote authenticated users to modify data, obtain sensitive information, or trigger outbound traffic to arbitrary external hosts by leveraging (1) stylesheet commands that are permitted by the libxslt security options or (2) an xslt_process feature, related to an XML External Entity (aka XXE) issue.

CVSS2: 4.9
EPSS: Низкий
redhat логотип

CVE-2012-3488

почти 13 лет назад

The libxslt support in contrib/xml2 in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 does not properly restrict access to files and URLs, which allows remote authenticated users to modify data, obtain sensitive information, or trigger outbound traffic to arbitrary external hosts by leveraging (1) stylesheet commands that are permitted by the libxslt security options or (2) an xslt_process feature, related to an XML External Entity (aka XXE) issue.

CVSS2: 3.8
EPSS: Низкий
nvd логотип

CVE-2012-3488

почти 13 лет назад

The libxslt support in contrib/xml2 in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 does not properly restrict access to files and URLs, which allows remote authenticated users to modify data, obtain sensitive information, or trigger outbound traffic to arbitrary external hosts by leveraging (1) stylesheet commands that are permitted by the libxslt security options or (2) an xslt_process feature, related to an XML External Entity (aka XXE) issue.

CVSS2: 4.9
EPSS: Низкий
debian логотип

CVE-2012-3488

почти 13 лет назад

The libxslt support in contrib/xml2 in PostgreSQL 8.3 before 8.3.20, 8 ...

CVSS2: 4.9
EPSS: Низкий
github логотип

GHSA-8wqv-9478-cg4h

около 3 лет назад

The libxslt support in contrib/xml2 in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 does not properly restrict access to files and URLs, which allows remote authenticated users to modify data, obtain sensitive information, or trigger outbound traffic to arbitrary external hosts by leveraging (1) stylesheet commands that are permitted by the libxslt security options or (2) an xslt_process feature, related to an XML External Entity (aka XXE) issue.

EPSS: Низкий
oracle-oval логотип

ELSA-2012-1264

почти 13 лет назад

ELSA-2012-1264: postgresql security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2012-1263

почти 13 лет назад

ELSA-2012-1263: postgresql and postgresql84 security update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2012-3488

The libxslt support in contrib/xml2 in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 does not properly restrict access to files and URLs, which allows remote authenticated users to modify data, obtain sensitive information, or trigger outbound traffic to arbitrary external hosts by leveraging (1) stylesheet commands that are permitted by the libxslt security options or (2) an xslt_process feature, related to an XML External Entity (aka XXE) issue.

CVSS2: 4.9
0%
Низкий
почти 13 лет назад
redhat логотип
CVE-2012-3488

The libxslt support in contrib/xml2 in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 does not properly restrict access to files and URLs, which allows remote authenticated users to modify data, obtain sensitive information, or trigger outbound traffic to arbitrary external hosts by leveraging (1) stylesheet commands that are permitted by the libxslt security options or (2) an xslt_process feature, related to an XML External Entity (aka XXE) issue.

CVSS2: 3.8
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2012-3488

The libxslt support in contrib/xml2 in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 does not properly restrict access to files and URLs, which allows remote authenticated users to modify data, obtain sensitive information, or trigger outbound traffic to arbitrary external hosts by leveraging (1) stylesheet commands that are permitted by the libxslt security options or (2) an xslt_process feature, related to an XML External Entity (aka XXE) issue.

CVSS2: 4.9
0%
Низкий
почти 13 лет назад
debian логотип
CVE-2012-3488

The libxslt support in contrib/xml2 in PostgreSQL 8.3 before 8.3.20, 8 ...

CVSS2: 4.9
0%
Низкий
почти 13 лет назад
github логотип
GHSA-8wqv-9478-cg4h

The libxslt support in contrib/xml2 in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 does not properly restrict access to files and URLs, which allows remote authenticated users to modify data, obtain sensitive information, or trigger outbound traffic to arbitrary external hosts by leveraging (1) stylesheet commands that are permitted by the libxslt security options or (2) an xslt_process feature, related to an XML External Entity (aka XXE) issue.

0%
Низкий
около 3 лет назад
oracle-oval логотип
ELSA-2012-1264

ELSA-2012-1264: postgresql security update (MODERATE)

почти 13 лет назад
oracle-oval логотип
ELSA-2012-1263

ELSA-2012-1263: postgresql and postgresql84 security update (MODERATE)

почти 13 лет назад

Уязвимостей на страницу