Vulnerability Name: | CVE-2003-0025 (CCN-11028) | ||||||||
Assigned: | 2003-01-08 | ||||||||
Published: | 2003-01-08 | ||||||||
Updated: | 2016-10-18 | ||||||||
Summary: | Multiple SQL injection vulnerabilities in IMP 2.2.8 and earlier allow remote attackers to perform unauthorized database activities and possibly gain privileges via certain database functions such as check_prefs() in db.pgsql, as demonstrated using mailbox.php3. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Data Manipulation | ||||||||
References: | Source: MITRE Type: CNA CVE-2003-0025 Source: CCN Type: Conectiva Linux Security Announcement CLSA-2003:690 imp Source: BUGTRAQ Type: UNKNOWN 20030108 IMP 2.x SQL injection vulnerabilities Source: CCN Type: BugTraq Mailing List, 2003-01-08 17:34:16 IMP 2.x SQL injection vulnerabilities Source: SECUNIA Type: UNKNOWN 8087 Source: SECUNIA Type: UNKNOWN 8177 Source: CCN Type: SECTRACK ID: 1005904 Horde IMP Mail Server Input Validation Holes May Let Remote Users Execute Commands on the Underlying Database Server Source: DEBIAN Type: Patch, Vendor Advisory DSA-229 Source: DEBIAN Type: DSA-229 imp -- SQL injection Source: CCN Type: Horde Web site IMP Webmail Client Source: CCN Type: OSVDB ID: 10105 Horde IMP mailbox.php3 Multiple Parameter SQL Injection Source: BUGTRAQ Type: UNKNOWN 20030108 Re: IMP 2.x SQL injection vulnerabilities Source: BID Type: UNKNOWN 6559 Source: CCN Type: BID-6559 Horde IMP Database Files SQL Injection Vulnerabilities Source: SECTRACK Type: UNKNOWN 1005904 Source: XF Type: UNKNOWN imp-multiple-sql-injection(11028) Source: SUSE Type: SUSE-SA:2003:0008 imp: remote system compromise | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |