First published: Fri Jul 04 2003(Updated: )
SQL injection vulnerability in the PostgreSQL authentication module (mod_sql_postgres) for ProFTPD before 1.2.9rc1 allows remote attackers to execute arbitrary SQL and gain privileges by bypassing authentication or stealing passwords via the USER name.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ProFTPD | =1.2.9_rc1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0500 is considered a critical vulnerability due to its potential for remote exploitation and unauthorized access.
To fix CVE-2003-0500, upgrade to ProFTPD version 1.2.9rc1 or later, which patches this SQL injection issue.
Exploiting CVE-2003-0500 allows attackers to execute arbitrary SQL commands, potentially bypassing authentication and stealing passwords.
CVE-2003-0500 affects ProFTPD versions before 1.2.9rc1 that use the PostgreSQL authentication module.
Yes, CVE-2003-0500 can be exploited remotely, allowing attackers to gain unauthorized access to the system.