courier-authlib: SQL injection
| Package(s): | courier-authlib | CVE #(s): | CVE-2008-2667 | ||||||||||||
| Created: | September 8, 2008 | Updated: | December 26, 2008 | ||||||||||||
| Description: | From the Gentoo advisory: It has been discovered that some input (e.g. the username) passed to the library are not properly sanitised before being used in SQL queries. A remote attacker could provide specially crafted input to the library, possibly resulting in the remote execution of arbitrary SQL commands. NOTE: Exploitation of this vulnerability requires that a MySQL database is used for authentication and that a Non-Latin character set is selected. | ||||||||||||||
| Alerts: |
| ||||||||||||||
