Description
The interactive installer in PostgreSQL before 9.3.15, 9.4.x before 9.4.10, and 9.5.x before 9.5.5 might allow remote attackers to execute arbitrary code by leveraging use of HTTP to download software.
Remediation
References
Related Vulnerabilities
XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-46731)
Jenkins Resource Management Errors Vulnerability (CVE-2014-3661)
WordPress Plugin WP REST API (WP API) Cross-Site Scripting (1.2.2)
Oracle HTTP Server Other Vulnerability (CVE-2002-0656)
MyBB Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3759)