CVE
- Id
- 6854
- CVE No.
- CVE-2003-0025
- Status
- Candidate
- Description
- Multiple SQL injection vulnerabilities in IMP 2.2.8 and earlier allow remote attackers to perform unauthorized database activities and possibly gain privileges via certain database functions such as check_prefs() in db.pgsql, as demonstrated using mailbox.php3.
- Phase
- Modified (20071121)
- Votes
- ACCEPT(3) Armstrong, Cole, Green | MODIFY(1) Jones | NOOP(2) Christey, Cox
- Comments
- Jones> Change "...gain privileges..." to "...gain additional | privileges..." | Christey> BID:6559 | URL:http://www.securityfocus.com/bid/6559 | XF:imp-multiple-sql-injection(11028) | URL:http://www.iss.net/security_center/static/11028.php | Christey> CONECTIVA:CLA-2003:690 | URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000690