Описание
mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROGRAM).
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| proftpd-dfsg | fixed | 1.3.9~dfsg-5 | package | |
| proftpd-dfsg | fixed | 1.3.8.c+dfsg-4+deb13u2 | trixie | package |
| proftpd-dfsg | fixed | 1.3.8+dfsg-4+deb12u5 | bookworm | package |
Примечания
https://github.com/proftpd/proftpd/issues/2052
EPSS
Связанные уязвимости
mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROGRAM).
mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROGRAM).
mod_sql in ProFTPD before 1.3.10rc1 allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROGRAM).
Уязвимость модуля mod_sql FTP-сервера ProFTPD, позволяющая нарушителю выполнить произвольные команды
EPSS