CVE
- Id
- 18928
- CVE No.
- CVE-2006-2824
- Status
- Candidate
- Description
- Logicalware MailManager before 2.0.10 does not remove 0xc8 0x27 (0xc8 followed by a single-quote character) from the data stream to the server, which allows remote attackers to modify data and gain administrative access when PostgreSQL is used, aka "bug #1494281 - Postgres encoding security hole." NOTE: while this issue involves PostgreSQL, it is specific to MailManager"s interface to PostgreSQL and is therefore a different vulnerability than CVE-2006-2313 and CVE-2006-2314.
- Phase
- Assigned (20060605)
- Votes
- None (candidate not yet proposed)
- Comments