CVE-2003-0040: SQL Injection
Published Feb 19, 2003
·Updated
SQL injection vulnerability in the PostgreSQL auth module for courier 0.40 and earlier allows remote attackers to execute SQL code via the user name.
Affected Software
2 affected components
Double Precision Incorporated Courier Mta=0.37.3
Inter7 Courier-imap=1.6
Remediation
Patch Available
Patch Available
Event History
Feb 19, 2003
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2003-0040?
CVE-2003-0040 is considered a high severity vulnerability due to its potential for remote code execution via SQL injection.
2
What software versions are affected by CVE-2003-0040?
CVE-2003-0040 affects Courier MTA versions 0.37.3 and earlier, as well as Courier-IMAP version 1.6.
3
How do I fix CVE-2003-0040?
To remediate CVE-2003-0040, upgrade to the latest version of Courier MTA or Courier-IMAP where the vulnerability is patched.
4
What type of vulnerability is CVE-2003-0040?
CVE-2003-0040 is classified as an SQL injection vulnerability affecting authentication processes.
5
Can CVE-2003-0040 be exploited remotely?
Yes, CVE-2003-0040 can be exploited remotely by attackers through crafted SQL queries sent via the user name.