Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | PostgreSQL Remote Code Executuon | https://github.com/wkjung0624/cve-2019-9193 | POC Details |
| 2 | CVE-2019–9193 - PostgreSQL 9.3-12.3 Authenticated Remote Code Execution | https://github.com/b4keSn4ke/CVE-2019-9193 | POC Details |
| 3 | PostgreSQL 9.3-11.7 - Remote Code Execution (RCE) | https://github.com/chromanite/CVE-2019-9193-PostgreSQL-9.3-11.7 | POC Details |
| 4 | None | https://github.com/paulotrindadec/CVE-2019-9193 | POC Details |
| 5 | is a PoC tool designed to exploit an authenticated Remote Code Execution (RCE) vulnerability in specific versions of PostgreSQL (9.3 - 11.7) | https://github.com/geniuszlyy/CVE-2019-9193 | POC Details |
| 6 | PoC tool designed to exploit an authenticated Remote Code Execution (RCE) vulnerability in certain versions of PostgreSQL (9.3 - 11.7) | https://github.com/AxthonyV/CVE-2019-9193 | POC Details |
| 7 | None | https://github.com/A0be/CVE-2019-9193 | POC Details |
| 8 | is a PoC tool designed to exploit an authenticated Remote Code Execution (RCE) vulnerability in specific versions of PostgreSQL (9.3 - 11.7) | https://github.com/geniuszly/CVE-2019-9193 | POC Details |
| 9 | None | https://github.com/corsisechero/CVE-2019-9193byVulHub | POC Details |
| 10 | In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute arbitrary code in the context of the database's operating system user. This functionality is enabled by default and can be abused to run arbitrary operating system commands on Windows, Linux, and macOS. NOTE: Third parties claim/state this is not an issue because PostgreSQL functionality for ‘COPY TO/FROM PROGRAM’ is acting as intended. References state that in PostgreSQL, a superuser can execute commands as the server user without using the ‘COPY FROM PROGRAM’. | https://github.com/projectdiscovery/nuclei-templates/blob/main/javascript/cves/2019/CVE-2019-9193.yaml | POC Details |
| 11 | None | https://github.com/Threekiii/Awesome-POC/blob/master/%E6%95%B0%E6%8D%AE%E5%BA%93%E6%BC%8F%E6%B4%9E/PostgreSQL%20%E9%AB%98%E6%9D%83%E9%99%90%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E%20CVE-2019-9193.md | POC Details |
| 12 | https://github.com/vulhub/vulhub/blob/master/postgres/CVE-2019-9193/README.md | POC Details | |
| 13 | PoC tool designed to exploit an authenticated Remote Code Execution (RCE) vulnerability in certain versions of PostgreSQL (9.3 - 11.7) | https://github.com/jhnhnck/CVE-2019-9193 | POC Details |
| 14 | This lab simulates CVE-2019-9193 - PostgreSQL COPY FROM PROGRAM RCE | https://github.com/netw0rk7/CVE-2019-9193-Home-Lab | POC Details |
| 15 | None | https://github.com/Cheryanika/CVE-2019-9193---Postgresql---RCE | POC Details |
| 16 | None | https://github.com/CybersRMUTL/CVE-2019-9193-Postgresql-RCE | POC Details |
No public POC found.
Login to generate AI POC| CVE-2018-17990 | D-Link DSL-3782 操作系统命令注入漏洞 | |
| CVE-2018-17565 | Grandstream GXP16xx VoIP 操作系统命令注入漏洞 | |
| CVE-2018-17564 | Grandstream GXP16xx VoIP 输入验证错误漏洞 | |
| CVE-2018-17563 | Grandstream GXP16xx VoIP 输入验证错误漏洞 | |
| CVE-2018-17989 | D-Link DSL-3782 跨站脚本漏洞 | |
| CVE-2018-19113 | Pronestor PNHM add-in 权限许可和访问控制问题漏洞 | |
| CVE-2019-6715 | WordPress W3 Total Cache插件信息泄露漏洞 | |
| CVE-2019-10686 | Ctrip Apollo 安全漏洞 | |
| CVE-2018-5757 | AudioCodes 450HD IP Phone 操作系统命令注入漏洞 | |
| CVE-2019-10684 | 迅易科技 74cms 代码注入漏洞 | |
| CVE-2019-5891 | OverIT Geocall 访问控制错误漏洞 | |
| CVE-2019-5890 | OverIT Geocall 授权问题漏洞 | |
| CVE-2019-5889 | OverIT Geocall 路径遍历漏洞 | |
| CVE-2019-5888 | OverIT Geocall 跨站脚本漏洞 |
No comments yet