CVE-2009-4795 EXPLOIT
6.8
MEDIUM · CVSS 2.0 · EPSS 2% (pctl 80)
Patch early
A public exploit exists.
Description
Multiple SQL injection vulnerabilities in Xlight FTP Server before 3.2.1, when ODBC authentication is enabled, allow remote attackers to execute arbitrary SQL commands via the (1) USER (aka username) or (2) PASS (aka password) command.
Scoring
| CVSS | 6.8 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
| EPSS | 2.03% — more likely to be exploited than 80% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2010-04-22 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| xlightftpd | xlight ftp server |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Xlight FTP Server 3.2 - 'user' SQL Injection | 2009-03-19 |
References
- http://secunia.com/advisories/34513
- http://www.securityfocus.com/bid/34288
- http://www.xlightftpd.com/forum/viewtopic.php?t=1042
- http://www.xlightftpd.com/whatsnew.htm
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49495
- http://secunia.com/advisories/34513
- http://www.securityfocus.com/bid/34288
- http://www.xlightftpd.com/forum/viewtopic.php?t=1042
- http://www.xlightftpd.com/whatsnew.htm
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49495
→ the Explorer · watch your stack · NVD