Description
PostgreSQL 9.2.x before 9.2.4 and 9.1.x before 9.1.9 does not properly check REPLICATION privileges, which allows remote authenticated users to bypass intended backup restrictions by calling the (1) pg_start_backup or (2) pg_stop_backup functions.
Remediation
References
Related Vulnerabilities
WebLogic Missing Authentication for Critical Function Vulnerability (CVE-2026-35303)
WordPress Plugin HTML5 MP3 Player with Playlist Free Information Disclosure (2.6)
phpMyFAQ 7PK - Security Features Vulnerability (CVE-2014-6050)
WordPress Plugin G-Lock Double Opt-in Manager 'ajaxbackend.php' SQL Injection (2.6.2)