CVE-2012-0811

Postfix Admin <2.3.5 - SQL Injection

Title source: llm
STIX 2.1

Description

Multiple SQL injection vulnerabilities in Postfix Admin (aka postfixadmin) before 2.3.5 allow remote authenticated users to execute arbitrary SQL commands via (1) the pw parameter to the pacrypt function, when mysql_encrypt is configured, or (2) unspecified vectors that are used in backup files generated by backup.php.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/51680
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/01/26/5
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/01/27/5

Scores

EPSS 0.0168
EPSS Percentile 74.6%

Details

CWE
CWE-89
Status published
Products (45)
postfix/postfix 2.0.0
postfix/postfix 2.0.1
postfix/postfix 2.0.2
postfix/postfix 2.0.3
postfix/postfix 2.0.4
postfix/postfix 2.0.5
postfix/postfix 2.0.6
postfix/postfix 2.0.7
postfix/postfix 2.0.8
postfix/postfix 2.0.9
... and 35 more
Published Oct 01, 2014
Tracked Since Feb 18, 2026