CVE-2009-4795

Multiple SQL injection vulnerabilities in Xlight FTP Server before 3.2.1, when ODBC authentication is enabled, allow remote attackers to execute arbitrary SQL commands via the (1) USER (aka username) or (2) PASS (aka password) command.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 39%
VendorProductVersion
xlightftpdxlight_ftp_server
𝑥
≤ 3.2
xlightftpdxlight_ftp_server
1.60
xlightftpdxlight_ftp_server
1.61
xlightftpdxlight_ftp_server
1.62
xlightftpdxlight_ftp_server
1.62a:a
xlightftpdxlight_ftp_server
1.64
xlightftpdxlight_ftp_server
1.65
xlightftpdxlight_ftp_server
2.0
xlightftpdxlight_ftp_server
2.01
xlightftpdxlight_ftp_server
2.1
xlightftpdxlight_ftp_server
2.2
xlightftpdxlight_ftp_server
2.02
xlightftpdxlight_ftp_server
2.03
xlightftpdxlight_ftp_server
2.8
xlightftpdxlight_ftp_server
2.24
xlightftpdxlight_ftp_server
2.27
xlightftpdxlight_ftp_server
2.40
xlightftpdxlight_ftp_server
2.60
xlightftpdxlight_ftp_server
2.70
xlightftpdxlight_ftp_server
2.72
xlightftpdxlight_ftp_server
2.82
xlightftpdxlight_ftp_server
2.83
xlightftpdxlight_ftp_server
2.85
xlightftpdxlight_ftp_server
2.86
xlightftpdxlight_ftp_server
2.706
xlightftpdxlight_ftp_server
2.835
xlightftpdxlight_ftp_server
2.861
xlightftpdxlight_ftp_server
3.0
xlightftpdxlight_ftp_server
3.0.5
xlightftpdxlight_ftp_server
3.1
xlightftpdxlight_ftp_server
3.1.1
xlightftpdxlight_ftp_server
3.1.5
xlightftpdxlight_ftp_server
3.1.6
𝑥
= Vulnerable software versions