Loading
SQL injection vulnerability in the LDAP and MySQL authentication patch for Cyrus SASL 1.5.24 and 1.5.27 allows remote attackers to execute arbitrary SQL commands and log in as arbitrary POP mail users via the password.
Use Cyrus vendor hub and Sasl product page to widen CVE-2002-2043 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2005-0373, CVE-2004-0884 and CVE-2006-1721 for nearby disclosures in the same product family.