Back
CVE-2004-1129
SQL injection vulnerability in (1) fdelmail.asp, (2) addressc.asp, and possibly (3) postmail.asp and (4) fmvmail.asp in CMailServer 5.2 allow remote attackers to inject arbitrary SQL commands and delete mail metadata or e-mail addresses of contacts via the indexOfMail parameter.
Published: Jan 10, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| youngzsoft | cmailserver | 5.2.0 |
GitHub Security Advisory GHSA-rm27-245w-3rmp
SQL injection vulnerability in (1) fdelmail.asp, (2) addressc.asp, and possibly (3) postmail.asp...
References (8)
- http://marc.info/?l=bugtraq&m=110137313329955&w=2
- http://www.security.org.sg/vuln/cmailserver52.html
- http://www.securityfocus.com/bid/11742 Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18281
- http://marc.info/?l=bugtraq&m=110137313329955&w=2
- http://www.security.org.sg/vuln/cmailserver52.html
- http://www.securityfocus.com/bid/11742 Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18281
Risk Scores
CVSS Score
10.0 / 10
EPSS Score
1.93%
Top 22% most likely to be exploited
Threat Score
40.6 / 100
Data Sources
NVD
EPSS
GitHub