Vulnerability Name:

CVE-2001-1369 (CCN-7110)

Assigned:2001-09-10
Published:2001-09-10
Updated:2008-09-10
Summary:Leon J Breedt pam-pgsql before 0.5.2 allows remote attackers to execute arbitrary SQL code and bypass authentication or modify user account records by injecting SQL statements into user or password fields.
CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Access
References:Source: FREEBSD
Type: UNKNOWN
FreeBSD-SA-02:14

Source: CCN
Type: FreeBSD Security Advisory FreeBSD-SA-02:14
pam-pgsql port authentication bypass

Source: CCN
Type: RUS-CERT Advisory 2001-09:01
Vulnerabilities in PAM and NSS modules using a PostgreSQL database

Source: MITRE
Type: CNA
CVE-2001-1369

Source: CCN
Type: SourceForge.net
Project: sysauth-pgsql

Source: XF
Type: Patch, Vendor Advisory
postgresql-pam-authentication-module(7110)

Source: CCN
Type: OSVDB ID: 5410
pam-pgsql SQL Injection

Source: CCN
Type: BID-3317
Joerg Wendland Pam-PSQL Remote SQL Query Manipulation Vulnerability

Source: CCN
Type: BID-3318
Alessandro Gardich Pam-PSQL Remote SQL Query Manipulation Vulnerability

Source: BID
Type: UNKNOWN
3319

Source: CCN
Type: BID-3319
Leon J Breedt Pam-PGSQL Remote SQL Query Manipulation Vulnerability

Source: XF
Type: UNKNOWN
postgresql-pam-authentication-module(7110)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:leon_j_breedt:pam-pgsql:0.5.1:*:*:*:*:*:*:*
  • OR cpe:/a:leon_j_breedt:pam-pgsql:0.5.2:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:freebsd:ports_collection:*:*:*:*:*:*:*:*
  • OR cpe:/a:leon_j_breedt:pam-pgsql:0.5.1:*:*:*:*:*:*:*
  • OR cpe:/a:leon_j_breedt:pam-pgsql:0.5.2:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    leon_j_breedt pam-pgsql 0.5.1
    leon_j_breedt pam-pgsql 0.5.2
    freebsd ports collection *
    leon_j_breedt pam-pgsql 0.5.1
    leon_j_breedt pam-pgsql 0.5.2