PostgreSQL stores usernames and passwords in plaintext in (1) pg_shadow and (2) pg_pwd, which allows attackers with sufficient privileges to gain access to databases.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=95659987018649&w=2 | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/4364 | vdb entry |
http://www.securityfocus.com/bid/1139 | exploit vdb entry vendor advisory |