Lucene search

K
cveMitreCVE-2005-1824
HistoryJun 02, 2005 - 4:00 a.m.

CVE-2005-1824

2005-06-0204:00:00
mitre
web.nvd.nist.gov
40
cve-2005-1824
sql injection
mailutils
authentication
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.4

Confidence

Low

EPSS

0.002

Percentile

51.7%

The sql_escape_string function in auth/sql.c for the mailutils SQL authentication module does not properly quote the "" (backslash) character, which is used as an escape character and makes the module vulnerable to SQL injection attacks.

Affected configurations

Nvd
Node
gnumailutilsMatch1.0.6.1.1
VendorProductVersionCPE
gnumailutils1.0.6.1.1cpe:2.3:a:gnu:mailutils:1.0.6.1.1:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.4

Confidence

Low

EPSS

0.002

Percentile

51.7%