Vulnerability Name:

CVE-2009-0542 (CCN-48951)

Assigned:2009-02-10
Published:2009-02-10
Updated:2018-10-11
Summary:SQL injection vulnerability in ProFTPD Server 1.3.1 through 1.3.2rc2 allows remote attackers to execute arbitrary SQL commands via a "%" (percent) character in the username, which introduces a "'" (single quote) character during variable substitution by mod_sql.
CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
6.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
6.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-89
Vulnerability Consequences:Data Manipulation
References:Source: CCN
Type: BugTraq Mailing List, Tue Feb 10 2009 - 13:49:53 CST
Another SQL injection in ProFTPd with mod_mysql (probably postgres as well)

Source: CCN
Type: BugTraq Mailing List, Tue Feb 10 2009 - 16:12:17 CST
Re: Another SQL injection in ProFTPd with mod_mysql (probably postgres as well)

Source: CCN
Type: ProFTPd Bugzilla Bug 3180
SQL injection vulnerability

Source: CONFIRM
Type: UNKNOWN
http://bugs.proftpd.org/show_bug.cgi?id=3180

Source: MITRE
Type: CNA
CVE-2009-0542

Source: SECUNIA
Type: UNKNOWN
34268

Source: GENTOO
Type: UNKNOWN
GLSA-200903-27

Source: DEBIAN
Type: UNKNOWN
DSA-1730

Source: DEBIAN
Type: DSA-1727
proftpd-dfsg -- SQL injection vulnerabilites

Source: DEBIAN
Type: DSA-1730
proftpd-dfsg -- SQL injection vulnerabilites

Source: CCN
Type: GLSA-200903-27
ProFTPD: Multiple vulnerabilities

Source: MANDRIVA
Type: UNKNOWN
MDVSA-2009:061

Source: CCN
Type: oss-security Mailing List, Wed, 11 Feb 2009 11:35:26 -0700
CVE request for proftpd

Source: MLIST
Type: UNKNOWN
[oss-security] 20090211 CVE request for proftpd

Source: MLIST
Type: UNKNOWN
[oss-security] 20090211 Re: CVE request for proftpd

Source: CCN
Type: oss-security Mailing List, Wed, 11 Feb 2009 11:16:14 -0800 (PST)
Re: CVE request for proftpd

Source: MLIST
Type: UNKNOWN
[oss-security] 20090211 Re: CVE request for proftpd

Source: CCN
Type: OSVDB ID: 51953
ProFTPD Server mod_sql username % Character Handling SQL Injection

Source: BUGTRAQ
Type: UNKNOWN
20090210 Another SQL injection in ProFTPd with mod_mysql (probably postgres as well)

Source: BUGTRAQ
Type: UNKNOWN
20090210 Re: Another SQL injection in ProFTPd with mod_mysql (probably postgres as well)

Source: BUGTRAQ
Type: UNKNOWN
20090210 ProFTPd with mod_mysql Authentication Bypass Exploit

Source: BUGTRAQ
Type: UNKNOWN
20090211 Re: Re: Another SQL injection in ProFTPd with mod_mysql (probably postgres as well)

Source: CCN
Type: BID-33722
ProFTPD 'mod_sql' Username SQL Injection Vulnerability

Source: XF
Type: UNKNOWN
proftpd-percent-sql-injection(48951)

Source: EXPLOIT-DB
Type: UNKNOWN
8037

Vulnerable Configuration:Configuration 1:
  • cpe:/a:proftpd_project:proftpd:1.3.1:*:*:*:*:*:*:*
  • OR cpe:/a:proftpd_project:proftpd:1.3.2:*:*:*:*:*:*:*
  • OR cpe:/a:proftpd_project:proftpd:1.3.2_rc2:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:proftpd:proftpd:1.3.1:*:*:*:*:*:*:*
  • OR cpe:/a:proftpd:proftpd:1.3.2:rc2:*:*:*:*:*:*
  • OR cpe:/a:proftpd:proftpd:1.3.2:rc1:*:*:*:*:*:*
  • OR cpe:/a:proftpd:proftpd:1.3.2:rc3:*:*:*:*:*:*
  • OR cpe:/a:proftpd:proftpd:1.3.2:rc4:*:*:*:*:*:*
  • AND
  • cpe:/o:gentoo:linux:*:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:3.0:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0::x86_64:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:3.0::x86_64:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2008.0::x86-64:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:4.0:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2008.0:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2008.1:x86_64:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2008.1:*:*:*:*:*:*:*
  • OR cpe:/o:mandriva:linux:2009.0:*:*:*:*:*:*:*
  • OR cpe:/o:mandriva:linux:2009.0:-:x86_64:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:5.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:113175
    P
    proftpd-1.3.5b-2.5 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:106597
    P
    proftpd-1.3.5b-2.5 on GA media (Moderate)
    2021-10-01
    oval:org.mitre.oval:def:12886
    P
    DSA-1727-1 proftpd-dfsg -- SQL injection vulnerabilites
    2014-06-23
    oval:org.mitre.oval:def:13553
    P
    DSA-1730-1 proftpd-dfsg -- SQL injection vulnerabilites
    2014-06-23
    oval:org.mitre.oval:def:7391
    P
    DSA-1730 proftpd-dfsg -- SQL injection vulnerabilities
    2014-06-23
    oval:org.mitre.oval:def:7963
    P
    DSA-1727 proftpd-dfsg -- SQL injection vulnerabilities
    2014-06-23
    oval:org.debian:def:1730
    V
    SQL injection vulnerabilites
    2009-03-02
    oval:org.debian:def:1727
    V
    SQL injection vulnerabilites
    2009-02-26
    BACK
    proftpd_project proftpd 1.3.1
    proftpd_project proftpd 1.3.2
    proftpd_project proftpd 1.3.2_rc2
    proftpd proftpd 1.3.1
    proftpd proftpd 1.3.2 rc2
    proftpd proftpd 1.3.2 rc1
    proftpd proftpd 1.3.2 rc3
    proftpd proftpd 1.3.2 rc4
    gentoo linux *
    mandrakesoft mandrake linux corporate server 3.0
    mandrakesoft mandrake linux corporate server 4.0
    mandrakesoft mandrake linux corporate server 4.0
    mandrakesoft mandrake linux corporate server 3.0
    mandrakesoft mandrake linux 2008.0
    debian debian linux 4.0
    mandrakesoft mandrake linux 2008.0
    mandrakesoft mandrake linux 2008.1 x86_64
    mandrakesoft mandrake linux 2008.1
    mandriva linux 2009.0
    mandriva linux 2009.0 -
    debian debian linux 5.0