Description
Multiple SQL injection vulnerabilities in Postfix Admin (aka postfixadmin) before 2.3.5 allow remote authenticated users to execute arbitrary SQL commands via (1) the pw parameter to the pacrypt function, when mysql_encrypt is configured, or (2) unspecified vectors that are used in backup files generated by backup.php.
References (5)
Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/51680
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/01/26/5
Exploit x_refsource_misc
http://www.codseq.it/advisories/multiple_vulnerabilities_in_postfixadmin
Various Sources x_refsource_confirm
https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3/CHANGELOG.TXT
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/01/27/5
Scores
EPSS
0.0168
EPSS Percentile
74.6%
Details
CWE
CWE-89
Status
published
Products (45)
postfix/postfix
2.0.0
postfix/postfix
2.0.1
postfix/postfix
2.0.2
postfix/postfix
2.0.3
postfix/postfix
2.0.4
postfix/postfix
2.0.5
postfix/postfix
2.0.6
postfix/postfix
2.0.7
postfix/postfix
2.0.8
postfix/postfix
2.0.9
... and 35 more
Published
Oct 01, 2014
Tracked Since
Feb 18, 2026