CVE-2009-0542

ProFTPD Server <1.3.2rc2 - SQL Injection

Title source: llm

Description

SQL injection vulnerability in ProFTPD Server 1.3.1 through 1.3.2rc2 allows remote attackers to execute arbitrary SQL commands via a "%" (percent) character in the username, which introduces a "'" (single quote) character during variable substitution by mod_sql.

Exploits (2)

exploitdb WRITEUP VERIFIED
by gat3way · textremotemultiple
https://www.exploit-db.com/exploits/8037
exploitdb WORKING POC VERIFIED
by AlpHaNiX · perlremotemultiple
https://www.exploit-db.com/exploits/32798

Scores

EPSS 0.5849
EPSS Percentile 98.2%

Classification

CWE
CWE-89
Status draft

Affected Products (3)

proftpd_project/proftpd
proftpd_project/proftpd
proftpd_project/proftpd

Timeline

Published Feb 12, 2009
Tracked Since Feb 18, 2026