7.5
CVSSv2

CVE-2004-0366

Published: 04/05/2004 Updated: 09/02/2024
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the libpam-pgsql library prior to 0.5.2 allows malicious users to execute arbitrary SQL statements.

Vulnerable Product Search on Vulmon Subscribe to Product

pam-pgsql pam-pgsql

Vendor Advisories

Primoz Bratanic discovered a bug in libpam-pgsql, a PAM module to authenticate using a PostgreSQL database The library does not escape all user-supplied data that are sent to the database An attacker could exploit this bug to insert SQL statements For the stable distribution (woody) this problem has been fixed in version 052-3woody2 For the u ...