mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROGRAM).
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.3.9bCPE matchmatch criteria | cpe:2.3:a:proftpd:proftpd:*:*:*:*:*:*:*:* | ||
>= 1.3.7b, < 1.3.9aCPE match | cpe:2.3:a:proftpd:proftpd:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.