CVE-2003-0500

SQL injection vulnerability in the PostgreSQL authentication module (mod_sql_postgres) for ProFTPD before 1.2.9rc1 allows remote attackers to execute arbitrary SQL and gain privileges by bypassing authentication or stealing passwords via the USER name.
Configurations

Configuration 1 (hide)

cpe:2.3:a:proftpd_project:proftpd:1.2.9_rc1:*:*:*:*:*:*:*

History

20 Nov 2024, 23:44

Type Values Removed Values Added
References () http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/005826.html - () http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/005826.html -
References () http://www.debian.org/security/2003/dsa-338 - Patch, Vendor Advisory () http://www.debian.org/security/2003/dsa-338 - Patch, Vendor Advisory

Information

Published : 2003-08-07 04:00

Updated : 2024-11-20 23:44


NVD link : CVE-2003-0500

Mitre link : CVE-2003-0500

CVE.ORG link : CVE-2003-0500


JSON object : View

Products Affected

proftpd_project

  • proftpd