CVE-2009-4795
Multiple SQL injection vulnerabilities in Xlight FTP Server before 3.2.1, when ODBC authentication is enabled, allow remote attackers to execute arbitrary SQL commands via the (1) USER (aka username) or (2) PASS (aka password) command.
- Affected products
- Xlight Ftp Server
- Xlightftpd Xlight Ftp Server
- ≤ 3.2, 1.60, 1.61, 1.62, 1.62a, 1.64, 1.65, 2.0, 2.01, 2.1, 2.2, 2.02, 2.03, 2.8, 2.24, 2.27, 2.40, 2.60, 2.70, 2.72, 2.82, 2.83, 2.85, 2.86, 2.706, 2.835, 2.861, 3.0, 3.0.5, 3.1, 3.1.1, 3.1.5, 3.1.6
- Fix
- Available
- CVSS 2.0
- 6.8 MEDIUM
- EPSS
- 2.0% (80th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2010-04-22
CVE-2009-4795 at NVD
1 known exploit for CVE-2009-4795
Proof-of-concept code and exploit modules indexed by Sploitus