PT-2009-6638 · Proftpd · Proftpd Server

Tj Saunders

·

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2009-0543

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ProFTPD Server version 1.3.1
Description The issue allows remote attackers to bypass SQL injection protection mechanisms via invalid, encoded multibyte characters, which are not properly handled in (1) mod sql mysql and (2) mod sql postgres. This can lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation of the vulnerabilities can be carried out remotely.
Recommendations For ProFTPD Server version 1.3.1, consider disabling the mod sql mysql and mod sql postgres modules until a patch is available to prevent SQL injection attacks. Restrict access to the ProFTPD Server to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-00985
BDU:2015-00986
BDU:2015-02086
BDU:2015-02087
BDU:2015-02088
BDU:2015-02089
CVE-2009-0543
DSA-1727-1
DSA-1730-1
OPENSUSE-SU-2024:10048-1

Affected Products

Proftpd Server