6.8
CVSSv2

CVE-2009-4795

Published: 22/04/2010 Updated: 17/08/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in Xlight FTP Server prior to 3.2.1, when ODBC authentication is enabled, allow remote malicious users to execute arbitrary SQL commands via the (1) USER (aka username) or (2) PASS (aka password) command.

Vulnerable Product Search on Vulmon Subscribe to Product

xlightftpd xlight ftp server 2.861

xlightftpd xlight ftp server 2.86

xlightftpd xlight ftp server 2.706

xlightftpd xlight ftp server 2.70

xlightftpd xlight ftp server 2.02

xlightftpd xlight ftp server 2.01

xlightftpd xlight ftp server 1.60

xlightftpd xlight ftp server

xlightftpd xlight ftp server 3.0.5

xlightftpd xlight ftp server 3.1.6

xlightftpd xlight ftp server 3.1.5

xlightftpd xlight ftp server 2.85

xlightftpd xlight ftp server 2.835

xlightftpd xlight ftp server 2.60

xlightftpd xlight ftp server 2.40

xlightftpd xlight ftp server 2.0

xlightftpd xlight ftp server 1.65

xlightftpd xlight ftp server 3.0

xlightftpd xlight ftp server 2.8

xlightftpd xlight ftp server 2.72

xlightftpd xlight ftp server 2.1

xlightftpd xlight ftp server 2.03

xlightftpd xlight ftp server 1.62

xlightftpd xlight ftp server 1.61

xlightftpd xlight ftp server 3.1.1

xlightftpd xlight ftp server 3.1

xlightftpd xlight ftp server 2.83

xlightftpd xlight ftp server 2.82

xlightftpd xlight ftp server 2.27

xlightftpd xlight ftp server 2.24

xlightftpd xlight ftp server 2.2

xlightftpd xlight ftp server 1.64

xlightftpd xlight ftp server 1.62a

Exploits

source: wwwsecurityfocuscom/bid/34288/info Xlight FTP Server is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the ...