PT-2009-6637 · Proftpd · Proftpd-Doc+6

Gat3Way

·

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2009-0542

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ProFTPD Server versions 1.3.1 through 1.3.2rc2 proftpd-doc (affected versions not specified) proftpd-mod-pgsql (affected versions not specified) proftpd-mod-mysql (affected versions not specified) proftpd (affected versions not specified) proftpd-mod-ldap (affected versions not specified) proftpd-basic (affected versions not specified)
Description The issue allows remote attackers to execute arbitrary SQL commands via a "%" (percent) character in the username, which introduces a "'" (single quote) character during variable substitution by mod sql. This can lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation of the vulnerabilities can be carried out remotely.
Recommendations For ProFTPD Server versions 1.3.1 through 1.3.2rc2, consider disabling the mod sql module until a patch is available. For proftpd-doc, proftpd-mod-pgsql, proftpd-mod-mysql, proftpd, proftpd-mod-ldap, and proftpd-basic, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-00985
BDU:2015-00986
BDU:2015-02086
BDU:2015-02087
BDU:2015-02088
BDU:2015-02089
CVE-2009-0542
DSA-1727-1
DSA-1730-1
OPENSUSE-SU-2024:10048-1

Affected Products

Proftpd Server
Proftpd
Proftpd-Basic
Proftpd-Doc
Proftpd-Mod-Ldap
Proftpd-Mod-Mysql
Proftpd-Mod-Pgsql