CVE-2009-0543

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
12/02/2009
Last modified:
09/04/2025

Description

ProFTPD Server 1.3.1, with NLS support enabled, allows remote attackers to bypass SQL injection protection mechanisms via invalid, encoded multibyte characters, which are not properly handled in (1) mod_sql_mysql and (2) mod_sql_postgres.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:proftpd:proftpd:1.3.1:*:*:*:*:*:*:*