CVE-2009-0542
ProFTPD Server <1.3.2rc2 - SQL Injection
Title source: llmDescription
SQL injection vulnerability in ProFTPD Server 1.3.1 through 1.3.2rc2 allows remote attackers to execute arbitrary SQL commands via a "%" (percent) character in the username, which introduces a "'" (single quote) character during variable substitution by mod_sql.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by AlpHaNiX · perlremotemultiple
https://www.exploit-db.com/exploits/32798
References (13)
Scores
EPSS
0.5849
EPSS Percentile
98.2%
Classification
CWE
CWE-89
Status
draft
Affected Products (3)
proftpd_project/proftpd
proftpd_project/proftpd
proftpd_project/proftpd
Timeline
Published
Feb 12, 2009
Tracked Since
Feb 18, 2026