SQL injection vulnerability in the gen_show_status function in functions.inc.php in Postfix Admin (aka postfixadmin) prior to 2.3.7 allows remote authenticated users to execute arbitrary SQL commands via a new alias.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
postfix admin project postfix admin 2.3.4 |
||
postfix admin project postfix admin 2.3.3 |
||
postfix admin project postfix admin 2.3.2 |
||
postfix admin project postfix admin 2.3.1 |
||
postfix admin project postfix admin |
||
postfix admin project postfix admin 2.3.5 |
||
postfix admin project postfix admin 2.3 |
||
postfix admin project postfix admin 2.2.1.1 |