← Back

Mod Auth Pgsql

mod_auth_pgsql

Vendor: Guiseppe Tanzilli And Matthias Eckermann • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Guiseppe Tanzilli And Matthias Eckermann
1Mod Auth Pgsql
Apr 16, 2026
Dec 31, 2005
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple format string vulnerabilities in logging functions in mod_auth_pgsql before 2.0.3, when used for user authentication against a PostgreSQL database, allows remote unauthenticated attackers to execute arbitrary co...Show more
Multiple format string vulnerabilities in logging functions in mod_auth_pgsql before 2.0.3, when used for user authentication against a PostgreSQL database, allows remote unauthenticated attackers to execute arbitrary code, as demonstrated via the username.Show less
1Guiseppe Tanzilli And Matthias Eckermann
1Mod Auth Pgsql
Apr 16, 2026
Aug 29, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
The PostgreSQL authentication modules (1) mod_auth_pgsql 0.9.5, and (2) mod_auth_pgsql_sys 0.9.4, allow remote attackers to bypass authentication and execute arbitrary SQL via a SQL injection attack on the user name.