← Back to CVE List

CVE-2017-16082

Published: 2018-06-07T02:29Z
Last Modified: 2024-11-21T03:15Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
A remote code execution vulnerability was found within the pg module when the remote database or query specifies a specially crafted column name. There are 2 likely scenarios in which one would likely be vulnerable. 1) Executing unsafe, user-supplied sql which contains a malicious column name. 2) Connecting to an untrusted database and executing a query which returns results where any of the column names are malicious. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt