Courier-IMAP Username SQL Injection Vulnerability
BID:6738
Info
Courier-IMAP Username SQL Injection Vulnerability
| Bugtraq ID: | 6738 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 28 2003 12:00AM |
| Updated: | Jan 28 2003 12:00AM |
| Credit: | This vulnerability was reported in the Courier-IMAP 1.7.0 changelog. |
| Vulnerable: |
Inter7 Courier-IMAP 1.6 Double Precision Incorporated Courier MTA 0.37.3 |
| Not Vulnerable: |
Inter7 Courier-IMAP 1.7 |
Discussion
Courier-IMAP Username SQL Injection Vulnerability
A SQL injection vulnerability exists in Courier-IMAP when running in conjunction with a PostgreSQL database. This issue occurs due to insufficient sanitization of supplied usernames during authentication, which are included in a SQL query.
It is possible to modify the logic of SQL queries through exploitation of this issue. It may also allow for the exploitation of latent vulnerabilities in the underlying database implementation.
A SQL injection vulnerability exists in Courier-IMAP when running in conjunction with a PostgreSQL database. This issue occurs due to insufficient sanitization of supplied usernames during authentication, which are included in a SQL query.
It is possible to modify the logic of SQL queries through exploitation of this issue. It may also allow for the exploitation of latent vulnerabilities in the underlying database implementation.
Exploit / POC
Courier-IMAP Username SQL Injection Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Courier-IMAP Username SQL Injection Vulnerability
References:
References:
- Courier-IMAP 1.7.0 Changelog (Courier-IMAP)