CVE-2009-0543
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 19%
from disclosure to weapon0 days
Published on NVDFeb 12
1st PoCFeb 10
exploitation probability
19%top 3% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
ProFTPD Server 1.3.1, with NLS support enabled, allows remote attackers to bypass SQL injection protection mechanisms via invalid, encoded multibyte characters, which are not properly handled in (1) mod_sql_mysql and (2) mod_sql_postgres.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/8037⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://bugs.proftpd.org/show_bug.cgi?id=3173http://secunia.com/advisories/34268http://security.gentoo.org/glsa/glsa-200903-27.xmlhttp://www.debian.org/security/2009/dsa-1730http://www.mandriva.com/security/advisories?name=MDVSA-2009:061http://www.openwall.com/lists/oss-security/2009/02/11/4http://www.openwall.com/lists/oss-security/2009/02/11/5