7.5
CVSSv2

CVE-2006-2824

Published: 05/06/2006 Updated: 08/03/2011
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Logicalware MailManager prior to 2.0.10 does not remove 0xc8 0x27 (0xc8 followed by a single-quote character) from the data stream to the server, which allows remote malicious users to modify data and gain administrative access when PostgreSQL is used, aka "bug #1494281 - Postgres encoding security hole." NOTE: while this issue involves PostgreSQL, it is specific to MailManager's interface to PostgreSQL and is therefore a different vulnerability than CVE-2006-2313 and CVE-2006-2314.

Vulnerable Product Search on Vulmon Subscribe to Product

logicalware mailmanager 2.0

logicalware mailmanager 2.0.8

logicalware mailmanager 2.0 r7

logicalware mailmanager 2.0.1

logicalware mailmanager 2.0.7

logicalware mailmanager 2.0.2

logicalware mailmanager 2.0.1 rc2

logicalware mailmanager 2.0.6

logicalware mailmanager 2.0.9

logicalware mailmanager 2.0.5

logicalware mailmanager 2.0.4

logicalware mailmanager 2.0.3