CVE-2014-2655
Beschrijving NL
SQL-injectiekwetsbaarheid in de gen_show_status-functie in functions.inc.php in Postfix Admin (ook bekend als postfixadmin) vóór 2.3.7 stelt op afstand geverifieerde gebruikers in staat om willekeurige SQL-opdrachten uit te voeren via een nieuwe alias.
Origineel (Engels) tonen
SQL injection vulnerability in the gen_show_status function in functions.inc.php in Postfix Admin (aka postfixadmin) before 2.3.7 allows remote authenticated users to execute arbitrary SQL commands via a new alias.