20030618 SQL Inject in ProFTPD login against Postgresql using mod_sqlmailing list
http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/005826.html CVE-2003-0500
ProFTPd 1.2.9 RC1 - 'mod_sql' SQL Injection
Record summary
CVE-2003-0500 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit.
Description
SQL injection vulnerability in the PostgreSQL authentication module (mod_sql_postgres) for ProFTPD before 1.2.9rc1 allows remote attackers to execute arbitrary SQL and gain privileges by bypassing authentication or stealing passwords via the USER name.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBProFTPd 1.2.9 RC1 - 'mod_sql' SQL InjectionExploitDB exploitby SpaineNot analyzed1 file
References
3DSA-338Vendor advisory
http://www.debian.org/security/2003/dsa-338 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2003-0500