CVE-2004-1722: SQL Injection
SQL injection vulnerability in calendar.html in Merak Mail Server 5.2.7 allows remote attackers to execute arbitrary SQL statements via the schedule parameter.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1722?
CVE-2004-1722 is considered a critical vulnerability due to its ability to allow remote attackers to execute arbitrary SQL statements.
How do I fix CVE-2004-1722?
To fix CVE-2004-1722, upgrade the Merak Mail Server to version 7.5.3 or later, which addresses this SQL injection vulnerability.
Who is affected by CVE-2004-1722?
CVE-2004-1722 affects users of Merak Mail Server version 5.2.7 and potentially other versions that have not patched the SQL injection vulnerability.
What types of attacks can be performed using CVE-2004-1722?
Using CVE-2004-1722, attackers can execute arbitrary SQL queries which may lead to data theft, modification, or deletion.
Is CVE-2004-1722 a common vulnerability?
CVE-2004-1722 represents a common type of vulnerability known as SQL injection, which has been prevalent in various applications over the years.