CVE

Id
6425  
CVE No.
CVE-2002-2043  
Status
Candidate  
Description
SQL injection vulnerability in the LDAP and MySQL authentication patch for Cyrus SASL 1.5.24 and 1.5.27 allows remote attackers to execute arbitrary SQL commands and log in as arbitrary POP mail users via the password.  
Phase
Assigned (20050714)  
Votes
None (candidate not yet proposed)  
Comments