This application requires Javascript for optimal performance.

FTP.Username.Remote.SQL.Injection

Release Date

Jan 05, 2012

Severity

high

Impact

System Compromise: Remote attackers can execute arbitrary script code in the context of the affected site.

Description

This indicates an attack attempt against an SQL Injection vulnerability in ProFTPD.

The vulnerability is caused by an error when the vulnerable software handles a specially crafted username. It allows a remote attacker to execute arbitrary SQL commands.

Affected Products

ProFTPD Project ProFTPD 1.3.2 rc2
ProFTPD Project ProFTPD 1.3.1

Recommended Actions

Upgrade to the latest version of ProFTPD (1.3.2 or later):
http://www.proftpd.org/

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2009-0542

Reference/s

http://www.securityfocus.com/bid/33722 (BugTraq)

Reference: VID-30517