BasiliX is a web-based mail application. It offers features such as mail attachments, address book, multiple language and theme support, and includes MySQL database server. Reportedly, user supplied input is not adequately filtered before being used within an SQL query. This may result in the disclosure of sensitive information contained in the database, or the ability to modify data. This issue has been reported in current versions of BasiliX. However, earlier versions may share this vulnerability.
BasiliX is a web-based mail application. It offers features such as mail attachments, address book, multiple language and theme support, and includes MySQL database server. Reportedly, user supplied input is not adequately filtered before being used within an SQL query. This may result in the disclosure of sensitive information contained in the database, or the ability to modify data. This issue has been reported in current versions of BasiliX. However, earlier versions may share this vulnerability.