6.8
CVSSv2

CVE-2010-4652

Published: 02/02/2011 Updated: 18/03/2011
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Heap-based buffer overflow in the sql_prepare_where function (contrib/mod_sql.c) in ProFTPD prior to 1.3.3d, when mod_sql is enabled, allows remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via a crafted username containing substitution tags, which are not properly handled during construction of an SQL query.

Vulnerable Product Search on Vulmon Subscribe to Product

proftpd proftpd 1.3.1

proftpd proftpd 1.3.0

proftpd proftpd 1.2.10

proftpd proftpd 1.3.3

proftpd proftpd 1.2.4

proftpd proftpd 1.2.3

proftpd proftpd 1.2.0

proftpd proftpd 1.2.8

proftpd proftpd 1.2.6

proftpd proftpd 1.3.2

proftpd proftpd 1.2.2

proftpd proftpd 1.2.1

proftpd proftpd 1.2.9

proftpd proftpd 1.2.7

proftpd proftpd 1.2.5

proftpd proftpd

Vendor Advisories

Several vulnerabilities have been discovered in ProFTPD, a versatile, virtual-hosting FTP daemon: CVE-2008-7265 Incorrect handling of the ABOR command could lead to denial of service through elevated CPU consumption CVE-2010-3867 Several directory traversal vulnerabilities have been discovered in the mod_site_misc module CVE-2010-456 ...

Github Repositories

Node-NMAP-Vulners NPM package enabling your [NodeJs] application to interface with the features of [NMAP] This package requires that [NMAP] is installed and available to the running node application If [VULNERS] script is installed, this package is able to parse the output to [NodeJs] UPDATE 102 Edited READMEMD UPDATE 101 Improved Service and Vulnerabilities integrat