Back

CVE-2002-2043

SQL injection vulnerability in the LDAP and MySQL authentication patch for Cyrus SASL 1.5.24 and 1.5.27 allows remote attackers to execute arbitrary SQL commands and log in as arbitrary POP mail users via the password.

Published: Dec 31, 2002 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (2)

Vendor Product Version
cyrus sasl 1.5.24
cyrus sasl 1.5.27

GitHub Security Advisory GHSA-hfpm-j2f9-7gcc

SQL injection vulnerability in the LDAP and MySQL authentication patch for Cyrus SASL 1.5.24 and...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.30%

Top 32% most likely to be exploited

Threat Score 30.4 / 100

Data Sources

NVD EPSS GitHub