CVE-2002-2043

SQL injection vulnerability in the LDAP and MySQL authentication patch for Cyrus SASL 1.5.24 and 1.5.27 allows remote attackers to execute arbitrary SQL commands and log in as arbitrary POP mail users via the password.

Scoring

CVSS base score
0.2
EPSS probability
4.10%
Published
2005-07-14
Last modified
2026-03-16

Affected products

Markdown version · Browse all CVEs