# CVE-2002-2043

## Summary

- **CVE ID:** CVE-2002-2043
- **Severity:** UNKNOWN
- **CVSS Score:** 0.2
- **CWE:** N/A
- **Published:** Jul 14, 2005
- **Last Modified:** Mar 16, 2026

## Description

SQL injection vulnerability in the LDAP and MySQL authentication patch for Cyrus SASL 1.5.24 and 1.5.27 allows remote attackers to execute arbitrary SQL commands and log in as arbitrary POP mail users via the password.

## Affected Products

- n/a — n/a (n/a)

## References

- [CNA](http://www.securityfocus.com/bid/4409)
- [CNA](http://www.iss.net/security_center/static/8748.php)
- [CNA](http://archives.neohapsis.com/archives/bugtraq/2002-04/0020.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 4.10%
- **EPSS Percentile:** 88.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._