SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2009-0543

ProFTPD Server 1.3.1, with NLS support enabled, allows remote attackers to bypass SQL injection protection mechanisms via invalid, encoded multibyte characters, which are not properly handled in (1) mod_sql_mysql and (2) mod_sql_postgres.

MEDIUM 6.8EPSS 18.7%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 18.7%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.

Description

ProFTPD Server 1.3.1, with NLS support enabled, allows remote attackers to bypass SQL injection protection mechanisms via invalid, encoded multibyte characters, which are not properly handled in (1) mod_sql_mysql and (2) mod_sql_postgres.

CVSS 2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
18.72% probability · 97th percentile
CISA KEV
Not listed
Weakness
CWE-89
Affected
proftpd/proftpd
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.