CVE-2009-2356 Information
Feb 14, 2021
cve
Description
Multiple stack-based buffer overflows in the pgsqlQuery function in NullLogic Groupware 1.2.7 when PostgreSQL is used might allow remote attackers to execute arbitrary code via input to the (1) POP3 (2) SMTP or (3) web component that triggers a long SQL query.
Reference
http://www.nth-dimension.org.uk/utils/get.php?downloadsid=55 http://www.securityfocus.com/archive/1/504737/100/0/threaded http://www.vupen.com/english/advisories/2009/1817
Share on: