CVE-2009-4795

EUVD-2009-4758
Multiple SQL injection vulnerabilities in Xlight FTP Server before 3.2.1, when ODBC authentication is enabled, allow remote attackers to execute arbitrary SQL commands via the (1) USER (aka username) or (2) PASS (aka password) command.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 38%
Affected Products (NVD)
VendorProductVersion
xlightftpdxlight_ftp_server
𝑥
≤ 3.2
xlightftpdxlight_ftp_server
1.60
xlightftpdxlight_ftp_server
1.61
xlightftpdxlight_ftp_server
1.62
xlightftpdxlight_ftp_server
1.62a:a
xlightftpdxlight_ftp_server
1.64
xlightftpdxlight_ftp_server
1.65
xlightftpdxlight_ftp_server
2.0
xlightftpdxlight_ftp_server
2.01
xlightftpdxlight_ftp_server
2.1
xlightftpdxlight_ftp_server
2.2
xlightftpdxlight_ftp_server
2.02
xlightftpdxlight_ftp_server
2.03
xlightftpdxlight_ftp_server
2.8
xlightftpdxlight_ftp_server
2.24
xlightftpdxlight_ftp_server
2.27
xlightftpdxlight_ftp_server
2.40
xlightftpdxlight_ftp_server
2.60
xlightftpdxlight_ftp_server
2.70
xlightftpdxlight_ftp_server
2.72
xlightftpdxlight_ftp_server
2.82
xlightftpdxlight_ftp_server
2.83
xlightftpdxlight_ftp_server
2.85
xlightftpdxlight_ftp_server
2.86
xlightftpdxlight_ftp_server
2.706
xlightftpdxlight_ftp_server
2.835
xlightftpdxlight_ftp_server
2.861
xlightftpdxlight_ftp_server
3.0
xlightftpdxlight_ftp_server
3.0.5
xlightftpdxlight_ftp_server
3.1
xlightftpdxlight_ftp_server
3.1.1
xlightftpdxlight_ftp_server
3.1.5
xlightftpdxlight_ftp_server
3.1.6
𝑥
= Vulnerable software versions