CVE Vulnerabilities

CVE-2002-2043

Published: Dec 31, 2002 | Modified: Nov 20, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

SQL injection vulnerability in the LDAP and MySQL authentication patch for Cyrus SASL 1.5.24 and 1.5.27 allows remote attackers to execute arbitrary SQL commands and log in as arbitrary POP mail users via the password.

Affected Software

Name Vendor Start Version End Version
Sasl Cyrus 1.5.24 (including) 1.5.24 (including)
Sasl Cyrus 1.5.27 (including) 1.5.27 (including)

References