CVE-2012-0811

Source
https://nvd.nist.gov/vuln/detail/CVE-2012-0811
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2012-0811.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2012-0811
Related
Published
2014-10-01T14:55:10Z
Modified
2025-04-12T10:46:40Z
Downstream
Summary
[none]
Details

Multiple SQL injection vulnerabilities in Postfix Admin (aka postfixadmin) before 2.3.5 allow remote authenticated users to execute arbitrary SQL commands via (1) the pw parameter to the pacrypt function, when mysql_encrypt is configured, or (2) unspecified vectors that are used in backup files generated by backup.php.

References

Affected packages

Debian:12 / postfixadmin

Package

Name
postfixadmin
Purl
pkg:deb/debian/postfixadmin?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.3.5-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / postfixadmin

Package

Name
postfixadmin
Purl
pkg:deb/debian/postfixadmin?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.3.5-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}