Posted by Filippo Cavallarin on Jan 30
Advisory ID: CSA-12002Title: Multiple vulnerabilities in postfixadmin
Product: postfixadmin
Version: 2.3.4 and probably prior
Vendor: www.postifixadmin.org
Vulnerability type: SQL injection, XSS
Vendor notification: 2012-01-10
Public disclosure: 2012-01-26
postfixadmin version 2.3.4 and probably below suffers from multiple vulnerabilities:
1) SQL injection in pacrypt function: if postfixadmin is configured with...