CVE-2006-2824 Information
Feb 14, 2021
cve
Description
Logicalware MailManager before 2.0.10 does not remove 0xc8 0x27 (0xc8 followed by a single-quote character) from the data stream to the server which allows remote attackers to modify data and gain administrative access when PostgreSQL is used aka \bug 1494281 - Postgres encoding security hole.\ NOTE: while this issue involves PostgreSQL it is specific to MailManager’s interface to PostgreSQL and is therefore a different vulnerability than CVE-2006-2313 and CVE-2006-2314.
Reference
http://secunia.com/advisories/20303 http://sourceforge.net/project/shownotes.php?group_id=85788&release_id=419822 http://svn.sourceforge.net/viewcvs.cgi/mailmanager/MailManager/branches/RELENG_2_1/sql/init.py?r1=3019&r2=3063 http://www.vupen.com/english/advisories/2006/1995
Share on: