Back

CVE-2003-1523

SQL injection vulnerability in the IMAP daemon in dbmail 1.1 allows remote attackers to execute arbitrary SQL commands via the (1) login username, (2) mailbox name, and possibly other attack vectors.

Published: Dec 31, 2003 Modified: Jun 16, 2026
CWE-89

CVSS Metrics

Affected Products (2)

Vendor Product Version
dbmail dbmail 1.0
dbmail dbmail 1.1

GitHub Security Advisory GHSA-5gcj-j7v3-fr39

SQL injection vulnerability in the IMAP daemon in dbmail 1.1 allows remote attackers to execute...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.06%

Top 38% most likely to be exploited

Threat Score 30.3 / 100

Data Sources

NVD EPSS GitHub