First published: Tue Aug 17 2004(Updated: )
SQL injection vulnerability in calendar.html in Merak Mail Server 5.2.7 allows remote attackers to execute arbitrary SQL statements via the schedule parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Merak Mail Server | =7.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1722 is considered a critical vulnerability due to its ability to allow remote attackers to execute arbitrary SQL statements.
To fix CVE-2004-1722, upgrade the Merak Mail Server to version 7.5.3 or later, which addresses this SQL injection vulnerability.
CVE-2004-1722 affects users of Merak Mail Server version 5.2.7 and potentially other versions that have not patched the SQL injection vulnerability.
Using CVE-2004-1722, attackers can execute arbitrary SQL queries which may lead to data theft, modification, or deletion.
CVE-2004-1722 represents a common type of vulnerability known as SQL injection, which has been prevalent in various applications over the years.