CVE-2014-2655

medium
Published 2014-04-02 · Modified 2026-05-06
CVSS v3
CVSS v2
6.5
VIR risk
6.5

Description

SQL injection vulnerability in the gen_show_status function in functions.inc.php in Postfix Admin (aka postfixadmin) before 2.3.7 allows remote authenticated users to execute arbitrary SQL commands via a new alias.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2014-2655

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://sourceforge.net/p/postfixadmin/code/1650

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed2.3.5-3
debian debianforkyfixed2.3.5-3
debian debiansidfixed2.3.5-3
debian debiantrixiefixed2.3.5-3

Application impact

VendorProductVersionsFixed
postfix_admin_projectpostfix_admin{"endIncluding":"2.3.6"}
postfix_admin_projectpostfix_admin2.2.1.1
postfix_admin_projectpostfix_admin2.3
postfix_admin_projectpostfix_admin2.3.1
postfix_admin_projectpostfix_admin2.3.2
postfix_admin_projectpostfix_admin2.3.3
postfix_admin_projectpostfix_admin2.3.4
postfix_admin_projectpostfix_admin2.3.5

References

CWEs

CWE-89

Verify integrity in audit chain (admin only). AS-IS.