Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In ProFTPD through 1.3.9a before 7666224, a SQL injection vulnerability in sqltab_fetch_clients_cb() in contrib/mod_wrap2_sql.c allows a remote attacker to inject arbitrary SQL commands via a crafted domain name that is accessed in a reverse DNS lookup. When "UseReverseDNS on" is enabled, the attacker-supplied hostname is passed unescaped into SQL queries. The character restrictions of DNS names may affect exploitability.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Vulnerability Title
ProFTPD SQL注入漏洞
Vulnerability Description
ProFTPD是ProFTPD开源的一套可配置性强的开放源代码的FTP服务器软件。 ProFTPD 1.3.9a之前版本存在SQL注入漏洞,该漏洞源于contrib/mod_wrap2_sql.c中sqltab_fetch_clients_cb()存在SQL注入,当启用UseReverseDNS on时,攻击者提供的域名在反向DNS查找中未经转义传递到SQL查询,可能导致远程攻击者通过特制域名注入任意SQL命令。
CVSS Information
N/A
Vulnerability Type
N/A