6.8
CVSSv2

CVE-2009-0543

Published: 12/02/2009 Updated: 09/06/2009
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

ProFTPD Server 1.3.1, with NLS support enabled, allows remote malicious users to bypass SQL injection protection mechanisms via invalid, encoded multibyte characters, which are not properly handled in (1) mod_sql_mysql and (2) mod_sql_postgres.

Vulnerable Product Search on Vulmon Subscribe to Product

proftpd proftpd 1.3.1

Vendor Advisories

Debian Bug report logs - #516388 proftpd: Several SQL injection vulnerabilities Package: proftpd; Maintainer for proftpd is (unknown); Reported by: Steffen Joeris <steffenjoeris@skolelinuxde> Date: Sat, 21 Feb 2009 05:24:01 UTC Severity: grave Tags: security Fixed in version proftpd-dfsg/132-1 Done: "Francesco P Lov ...
The security update for proftpd-dfsg in DSA-1727-1 caused a regression with the postgresql backend This update corrects the flaw Also it was discovered that the oldstable distribution (etch) is not affected by the security issues For reference the original advisory follows Two SQL injection vulnerabilities have been found in proftpd, a virtual- ...
Two SQL injection vulnerabilities have been found in proftpd, a virtual-hosting FTP daemon The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-0542 Shino discovered that proftpd is prone to an SQL injection vulnerability via the use of certain characters in the username CVE-2009-0543 TJ Saunde ...

Exploits

Just found out a problem with proftpd's sql authentication The problem is easily reproducible if you login with username like: USER %') and 1=2 union select 1,1,uid,gid,homedir,shell from users; -- and a password of "1" (without quotes) which leads to a successful login Different account logins can be made successful using the limit clase (e ...

Github Repositories

Node-NMAP-Vulners NPM package enabling your [NodeJs] application to interface with the features of [NMAP] This package requires that [NMAP] is installed and available to the running node application If [VULNERS] script is installed, this package is able to parse the output to [NodeJs] UPDATE 102 Edited READMEMD UPDATE 101 Improved Service and Vulnerabilities integrat