SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  PostgreSQL Interactive Tool SQL Injection

Category: DB-ATTACKS      

Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns.

References
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0959


Relevant Information