AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2007-3278

MEDIUM · CVSS 6.9 EPSS 1.26%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2007-06-19 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2007-3278
Severity
MEDIUM
CVSS
6.9
EPSS
1.26%

Original Filing — NVD Description

PostgreSQL 8.1 and probably later versions, when local trust authentication is enabled and the Database Link library (dblink) is installed, allows remote attackers to access arbitrary accounts and execute arbitrary SQL queries via a dblink host parameter that proxies the connection from 127.0.0.1.