CVE-2003-0040

EPSS 0.49%

courier-ssl - missing input sanitizing

Published: 2/19/2003Modified: 4/28/2026
Also known as:DSA-247DEBIAN-CVE-2003-0040

Description

SQL injection vulnerability in the PostgreSQL auth module for courier 0.40 and earlier allows remote attackers to execute SQL code via the user name.

Affected packages (2)

References (1)