Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Unknown

CVE-2001-0201

Disclosure Date: March 26, 2001 (last updated February 22, 2025)
The Postaci frontend for PostgreSQL does not properly filter characters such as semicolons, which could allow remote attackers to execute arbitrary SQL queries via the deletecontact.php program.
0
Attacker Value
Unknown

CVE-2000-1100

Disclosure Date: January 09, 2001 (last updated February 22, 2025)
The default configuration for PostACI webmail system installs the /includes/global.inc configuration file within the web root, which allows remote attackers to read sensitive information such as database usernames and passwords via a direct HTTP GET request.
0