CVE-2003-0025: SQL Injection
Published Jan 15, 2003
·Updated
Multiple SQL injection vulnerabilities in IMP 2.2.8 and earlier allow remote attackers to perform unauthorized database activities and possibly gain privileges via certain database functions such as checkprefs() in db.pgsql, as demonstrated using mailbox.php3.
Affected Software
9 affected components
Horde IMP=2.2
Horde IMP=2.2.1
Horde IMP=2.2.2
Horde IMP=2.2.3
Horde IMP=2.2.4
Horde IMP=2.2.5
Horde IMP=2.2.6
Horde IMP=2.2.7
Horde IMP=2.2.8
Remediation
Patch Available
Event History
Jan 15, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Jan 17, 2003
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0025?
CVE-2003-0025 is considered a critical severity vulnerability that allows for unauthorized database access.
2
How do I fix CVE-2003-0025?
To fix CVE-2003-0025, upgrade to Horde IMP version 2.2.9 or later.
3
What versions are affected by CVE-2003-0025?
CVE-2003-0025 affects Horde IMP versions 2.2.0 to 2.2.8.
4
How does CVE-2003-0025 allow database access?
CVE-2003-0025 allows remote attackers to exploit SQL injection vulnerabilities present in certain database functions.
5
What are the consequences of CVE-2003-0025 exploitation?
Exploitation of CVE-2003-0025 can lead to unauthorized activities in the database and potential privilege escalation.