Описание
SQL injection vulnerability in the gen_show_status function in functions.inc.php in Postfix Admin (aka postfixadmin) before 2.3.7 allows remote authenticated users to execute arbitrary SQL commands via a new alias.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 2.3.5-3 |
| lucid | DNE | |
| precise | DNE | |
| quantal | released | 2.3.5-2+deb7u1build0.12.10.1 |
| saucy | released | 2.3.5-2+deb7u1build0.13.10.1 |
| upstream | needs-triage |
Показывать по
Ссылки на источники
6.5 Medium
CVSS2
Связанные уязвимости
SQL injection vulnerability in the gen_show_status function in functions.inc.php in Postfix Admin (aka postfixadmin) before 2.3.7 allows remote authenticated users to execute arbitrary SQL commands via a new alias.
SQL injection vulnerability in the gen_show_status function in functio ...
SQL injection vulnerability in the gen_show_status function in functions.inc.php in Postfix Admin (aka postfixadmin) before 2.3.7 allows remote authenticated users to execute arbitrary SQL commands via a new alias.
6.5 Medium
CVSS2