|
|
| |
|
| |
proftpd: SQL injection
| Package(s): | proftpd |
CVE #(s): | |
| Created: | June 30, 2003 |
Updated: | June 30, 2003 |
| Description: |
runlevel [runlevel@raregazz.org] reported that ProFTPD's PostgreSQL
authentication module is vulnerable to a SQL injection attack. This
vulnerability could be exploited by a remote, unauthenticated attacker
to execute arbitrary SQL statements, potentially exposing the
passwords of other users, or to connect to ProFTPD as an arbitrary
user without supplying the correct password. |
| Alerts: |
|
( Log in to post comments)
|
|
|