CVE-2003-0040

5 documents5 sources
Severity
7.5HIGH
EPSS
0.5%
top 34.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 19
Latest updateApr 29

Description

SQL injection vulnerability in the PostgreSQL auth module for courier 0.40 and earlier allows remote attackers to execute SQL code via the user name.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages3 packages

Patches

🔴Vulnerability Details

3
GHSA
GHSA-vrgp-v3rr-v9mg: SQL injection vulnerability in the PostgreSQL auth module for courier 02022-04-29
CVEList
CVE-2003-0040: SQL injection vulnerability in the PostgreSQL auth module for courier 02004-09-01
OSV
CVE-2003-0040: SQL injection vulnerability in the PostgreSQL auth module for courier 02003-02-19

📋Vendor Advisories

1
Debian
CVE-2003-0040: courier - SQL injection vulnerability in the PostgreSQL auth module for courier 0.40 and e...2003
CVE-2003-0040 (HIGH CVSS 7.5) | SQL injection vulnerability in the | cvebase.io