VYPR

Pam Pgsql

by Leon J Breedt

CVEs (2)

  • CVE-2003-0672Aug 27, 2003
    risk 0.00cvss epss 0.03

    Format string vulnerability in pam-pgsql 0.5.2 and earlier allows remote attackers to execute arbitrary code via the username that isp rovided during authentication, which is not properly handled when recording a log message.

  • CVE-2001-1369Sep 10, 2001
    risk 0.00cvss epss 0.02

    Leon J Breedt pam-pgsql before 0.5.2 allows remote attackers to execute arbitrary SQL code and bypass authentication or modify user account records by injecting SQL statements into user or password fields.