Vulnerabilities > CVE-2001-1090 - Remote SQL Query Manipulation vulnerability in Alessandro Gardich NSS Postgresql 0.6.1

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
alessandro-gardich

Summary

nss_postgresql 0.6.1 and before allows a remote attacker to execute arbitrary SQL queries by inserting SQL code into an HTTP request.

Vulnerable Configurations

Part Description Count
Application
Alessandro_Gardich
1