CVE-2002-2043

4 documents4 sources
Severity
7.5HIGH
EPSS
4.1%
top 11.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 31
Latest updateApr 30

Description

SQL injection vulnerability in the LDAP and MySQL authentication patch for Cyrus SASL 1.5.24 and 1.5.27 allows remote attackers to execute arbitrary SQL commands and log in as arbitrary POP mail users via the password.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages1 packages

NVDcyrus/sasl1.5.24, 1.5.27+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-hfpm-j2f9-7gcc: SQL injection vulnerability in the LDAP and MySQL authentication patch for Cyrus SASL 12022-04-30
CVEList
CVE-2002-2043: SQL injection vulnerability in the LDAP and MySQL authentication patch for Cyrus SASL 12005-07-14

📋Vendor Advisories

1
Red Hat
CVE-2002-2043: SQL injection vulnerability in the LDAP and MySQL authentication patch for Cyrus SASL 1
CVE-2002-2043 (HIGH CVSS 7.5) | SQL injection vulnerability in the | cvebase.io