peter bassill · operator
$ cve CVE-2009-0543 JSON

CVE-2009-0543 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 15.8% (pctl 97)

Patch early

A public exploit exists.

Description

ProFTPD Server 1.3.1, with NLS support enabled, allows remote attackers to bypass SQL injection protection mechanisms via invalid, encoded multibyte characters, which are not properly handled in (1) mod_sql_mysql and (2) mod_sql_postgres.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS15.77% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2009-02-12
Last modified2026-06-16

Affected (1)

VendorProduct
proftpdproftpd

Public exploits

SourceTitleDate
exploit-dbProFTPd - 'mod_mysql' Authentication Bypass2009-02-10

References

→ the Explorer  ·  watch your stack  ·  NVD