vendor:
ProFTPD
by:
AlpHaNiX
7.5
CVSS
HIGH
SQL-injection
89
CWE
Product Name: ProFTPD
Affected Version From: 1.3.2001
Affected Version To: 1.3.2 rc 2
Patch Exists: YES
Related CWE: N/A
CPE: a:proftpd:proftpd
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
ProFTPD SQL-injection Vulnerability
ProFTPD is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. Exploiting this issue could allow an attacker to manipulate SQL queries, modify data, or exploit latent vulnerabilities in the underlying database. This may result in unauthorized access and a compromise of the application; other attacks are also possible.
Mitigation:
Input validation should be used to prevent SQL-injection attacks.