Command execution

PostgreSQL reaches OS command execution more directly than MySQL because the primitives are built into the server. Both routes need a privileged role, and both usually need a stacked query so a statement of their own can run.

The simplest route is COPY ... FROM PROGRAM, which runs a shell command and captures its output into a table. It requires a superuser or the pg_execute_server_program role and exists from PostgreSQL 9.3.

The second route defines a function in an untrusted language. Creating functions in plpythonu, plperlu, or C requires a superuser, and once created the function runs native code, so a wrapper around subprocess or system() gives command execution callable from SQL.

Pages#

References#

  • PostgreSQL Documentation: COPY ... FROM PROGRAM, CREATE FUNCTION, procedural languages
  • OWASP Testing Guide: Testing for SQL Injection

Cookie Consent

We use cookies to enhance your experience. Learn more