A vulnerability, which was classified as critical, has been found in web-cyradm. Affected by this issue is some unknown functionality of the file auth.inc.php. The manipulation of the argument login/login_password/LANG leads to sql injection. The attack may be launched remotely. The name of the patch is 2bcbead3bdb5f118bf2c38c541eaa73c29dcc90f. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-217640.
History

Wed, 09 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2023-01-08T09:18:54.836Z

Updated: 2025-04-09T14:43:42.572Z

Reserved: 2023-01-08T09:18:16.366Z

Link: CVE-2007-10002

cve-icon Vulnrichment

Updated: 2024-08-07T16:18:20.685Z

cve-icon NVD

Status : Modified

Published: 2023-01-08T10:15:10.950

Modified: 2024-11-21T00:27:15.610

Link: CVE-2007-10002

cve-icon Redhat

No data.