Vulnerability Report

CVE-2006-2314

Title: Postgresql Injection (SQLi/OSi)

SQLi

Proof Of Concept

No public PoC currently indexed for CVE-2006-2314.

CWE Category NVD-CWE-noinfo
Published Date May 24, 2006
Modified Date Jun 16, 2026
Exploit Status Not Found
Score 7.5 CVSS v2.0
Exploit Probability (EPSS)
2.79%

Vulnerability Summary

CVE-2006-2314: PostgreSQL 8.1.x before 8.1.4, 8.0.x before 8.0.8, 7.4.x before 7.4.13, 7.3.x before 7.3.15, and earlier versions allows context-dependent attackers to bypass SQL injection protection methods in applications that use multibyte encodings that allow the "\" (backslash) byte 0x5c to be the trailing byte of a multibyte character, such as SJIS, BIG5, GBK, GB18030, and UHC, which cannot be handled correctly by a client that does not understand multibyte encodings, aka a second variant of "Encoding-Based SQL Injection." NOTE: it could be argued that this is a class of issue related to interaction errors between the client and PostgreSQL, but a CVE has been assigned since PostgreSQL is treating this as a preventative measure against this class of problem.

Impacted Vendors

Reference Links

ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc http://archives.postgresql.org/pgsql-announce/2006-05/msg00010.php http://lists.suse.com/archive/suse-security-announce/2006-Jun/0002.html http://secunia.com/advisories/20231 http://secunia.com/advisories/20232 http://secunia.com/advisories/20314 http://secunia.com/advisories/20435 http://secunia.com/advisories/20451 http://secunia.com/advisories/20503 http://secunia.com/advisories/20555 http://secunia.com/advisories/20653 http://secunia.com/advisories/20782 http://secunia.com/advisories/21001 http://secunia.com/advisories/21749 http://security.gentoo.org/glsa/glsa-200607-04.xml http://securitytracker.com/id?1016142 http://support.avaya.com/elmodocs2/security/ASA-2006-113.htm http://www.debian.org/security/2006/dsa-1087 http://www.mandriva.com/security/advisories?name=MDKSA-2006:098 http://www.novell.com/linux/security/advisories/2006_21_sr.html http://www.osvdb.org/25731 http://www.postgresql.org/docs/techdocs.50 http://www.redhat.com/support/errata/RHSA-2006-0526.html http://www.securityfocus.com/archive/1/435038/100/0/threaded http://www.securityfocus.com/archive/1/435161/100/0/threaded http://www.securityfocus.com/bid/18092 http://www.trustix.org/errata/2006/0032/ http://www.ubuntu.com/usn/usn-288-2 http://www.ubuntu.com/usn/usn-288-3 http://www.vupen.com/english/advisories/2006/1941 https://exchange.xforce.ibmcloud.com/vulnerabilities/26627 https://exchange.xforce.ibmcloud.com/vulnerabilities/26628 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9947 https://usn.ubuntu.com/288-1/ ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc http://archives.postgresql.org/pgsql-announce/2006-05/msg00010.php http://lists.suse.com/archive/suse-security-announce/2006-Jun/0002.html http://secunia.com/advisories/20231 http://secunia.com/advisories/20232 http://secunia.com/advisories/20314 http://secunia.com/advisories/20435 http://secunia.com/advisories/20451 http://secunia.com/advisories/20503 http://secunia.com/advisories/20555 http://secunia.com/advisories/20653 http://secunia.com/advisories/20782 http://secunia.com/advisories/21001 http://secunia.com/advisories/21749 http://security.gentoo.org/glsa/glsa-200607-04.xml http://securitytracker.com/id?1016142 http://support.avaya.com/elmodocs2/security/ASA-2006-113.htm http://www.debian.org/security/2006/dsa-1087 http://www.mandriva.com/security/advisories?name=MDKSA-2006:098 http://www.novell.com/linux/security/advisories/2006_21_sr.html http://www.osvdb.org/25731 http://www.postgresql.org/docs/techdocs.50 http://www.redhat.com/support/errata/RHSA-2006-0526.html http://www.securityfocus.com/archive/1/435038/100/0/threaded http://www.securityfocus.com/archive/1/435161/100/0/threaded http://www.securityfocus.com/bid/18092 http://www.trustix.org/errata/2006/0032/ http://www.ubuntu.com/usn/usn-288-2 http://www.ubuntu.com/usn/usn-288-3 http://www.vupen.com/english/advisories/2006/1941 https://exchange.xforce.ibmcloud.com/vulnerabilities/26627 https://exchange.xforce.ibmcloud.com/vulnerabilities/26628 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9947 https://usn.ubuntu.com/288-1/
CVSS v2.0
Source Entity [email protected]
Severity HIGH
7.5
Access Vector
N/A
Authentication
N/A
RAW VECTOR AV:N/AC:L/Au:N/C:P/I:P/A:P

Associated Attack Patterns (CAPEC)

Total: Patterns

CVE-2006-2314 Exploits & PoCs (Proof Of Concept)

No public PoCs found in our database for this CVE.

MODIFIED

Vulnerability data updated via NVD.

MODIFIED

Vulnerability data or affected products updated.

PUBLISHED

Vulnerability first announced in NVD.

Attack Vector Matrix

Access Vector N/A
Complexity N/A
Privileges N/A
Interaction NONE
CVSS Vector String AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected Stack

No specific products linked.