7.5
CVSSv2

CVE-2003-0040

Published: 19/02/2003 Updated: 10/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the PostgreSQL auth module for courier 0.40 and previous versions allows remote malicious users to execute SQL code via the user name.

Vulnerable Product Search on Vulmon Subscribe to Product

inter7 courier-imap 1.6

double precision incorporated courier mta 0.37.3

Vendor Advisories

The developers of courier, an integrated user side mail server, discovered a problem in the PostgreSQL auth module Not all potentially malicious characters were sanitized before the username was passed to the PostgreSQL engine An attacker could inject arbitrary SQL commands and queries exploiting this vulnerability The MySQL auth module is not a ...