Back
CVE-2002-2043
SQL injection vulnerability in the LDAP and MySQL authentication patch for Cyrus SASL 1.5.24 and 1.5.27 allows remote attackers to execute arbitrary SQL commands and log in as arbitrary POP mail users via the password.
Published: Dec 31, 2002
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (2)
| Vendor | Product | Version |
|---|---|---|
| cyrus | sasl | 1.5.24 |
| cyrus | sasl | 1.5.27 |
GitHub Security Advisory GHSA-hfpm-j2f9-7gcc
SQL injection vulnerability in the LDAP and MySQL authentication patch for Cyrus SASL 1.5.24 and...
References (6)
- http://archives.neohapsis.com/archives/bugtraq/2002-04/0020.html Patch
- http://www.iss.net/security_center/static/8748.php Patch
- http://www.securityfocus.com/bid/4409 Patch
- http://archives.neohapsis.com/archives/bugtraq/2002-04/0020.html Patch
- http://www.iss.net/security_center/static/8748.php Patch
- http://www.securityfocus.com/bid/4409 Patch
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
1.30%
Top 32% most likely to be exploited
Threat Score
30.4 / 100
Data Sources
NVD
EPSS
GitHub