CVE-2009-0542

Aliases:DEBIAN-CVE-2009-0542
Advisory lineage Upstream: 0 Downstream: 4
Modified
Published: 12 Feb 2009, 16:00
Last modified:07 Aug 2024, 04:40

Vulnerability Summary

Overall Risk (default)
high
55/100
CVSS Score
7.5 HIGH
v2.0 (nvd)
EPSS Score
73.79% CRITICAL
74% probability +15.30%
KEV
Not listed
Ransomware
No reports
Public exploits
2 found
Dark Web
Not detected

Timeline

12 Feb 2009, 16:00
Published
Vulnerability first disclosed
07 Aug 2024, 04:40
Last Modified
Vulnerability information updated

Description

SQL injection vulnerability in ProFTPD Server 1.3.1 through 1.3.2rc2 allows remote attackers to execute arbitrary SQL commands via a "%" (percent) character in the username, which introduces a "'" (single quote) character during variable substitution by mod_sql.

CVSS Metrics

  • v2.0•HIGH•Score: 7.5AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 73.79%• Percentile: 99%

Techniques & Countermeasures

  • CWE-89•Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

    The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Affected Systems

  • debian•proftpd-dfsg

    < 1.3.2-1 | < 1.3.2-1 | < 1.3.2-1 | < 1.3.2-1

  • proftpd_project•proftpd

    1.3.1 | 1.3.2 | 1.3.2_rc2

References (14)