CVE-2014-2655
EPSS 0.52%postfixadmin - security update
Published: 4/2/2014Modified: 4/28/2026
Also known as:DEBIAN-CVE-2014-2655
Description
SQL injection vulnerability in the gen_show_status function in functions.inc.php in Postfix Admin (aka postfixadmin) before 2.3.7 allows remote authenticated users to execute arbitrary SQL commands via a new alias.
Affected packages (2)
- Debian/postfixadminfrom 0, < 2.3.5-3
- Debian/postfixadminfrom 0, < 2.3.5-2+deb7u1