Back

CVE-2003-0040

SQL injection vulnerability in the PostgreSQL auth module for courier 0.40 and earlier allows remote attackers to execute SQL code via the user name.

Published: Feb 19, 2003 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (2)

Vendor Product Version
double_precision_incorporated courier_mta 0.37.3
inter7 courier-imap 1.6

GitHub Security Advisory GHSA-vrgp-v3rr-v9mg

SQL injection vulnerability in the PostgreSQL auth module for courier 0.40 and earlier allows...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.23%

Top 34% most likely to be exploited

Threat Score 30.4 / 100

Data Sources

NVD EPSS GitHub