积极预防 及时发现
快速响应 力保恢复
PostgreSQL 把明文用户名和口令存储在pg_shadow 和 pg_pwd中,这允许攻击者有...
发布时间:2001-08-31 信息来源:管理员

CNCVE编号:CNCVE-20001199 CVE编号:CAN-2000-1199 安全级别:中 漏洞中文描述: PostgreSQL 把明文用户名和口令存储在pg_shadow 和 pg_pwd中,这允许攻击者有充分的权限来访问数据库。 漏洞英文描述: PostgreSQL stores usernames and passwords in plaintext in (1) pg_shadow and (2) pg_pwd, which allows attackers with sufficient privileges to gain access to databases. 漏洞参考: Reference: BUGTRAQ:20000423 Postgresql cleartext password storage Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=95659987018649&w=2 Reference: XF:postgresql-plaintext-passwords(4364) Reference: URL:http://xforce.iss.net/static/4364.php Ref 系统类型: 其他 漏洞类型:设计错误