CVE-2009-4795

Multiple SQL injection vulnerabilities in Xlight FTP Server before 3.2.1, when ODBC authentication is enabled, allow remote attackers to execute arbitrary SQL commands via the (1) USER (aka username) or (2) PASS (aka password) command.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
xlightftpdxlight_ftp_server
𝑥
≤ 3.2
xlightftpdxlight_ftp_server
1.60
xlightftpdxlight_ftp_server
1.61
xlightftpdxlight_ftp_server
1.62
xlightftpdxlight_ftp_server
1.62a:a
xlightftpdxlight_ftp_server
1.64
xlightftpdxlight_ftp_server
1.65
xlightftpdxlight_ftp_server
2.0
xlightftpdxlight_ftp_server
2.01
xlightftpdxlight_ftp_server
2.1
xlightftpdxlight_ftp_server
2.2
xlightftpdxlight_ftp_server
2.02
xlightftpdxlight_ftp_server
2.03
xlightftpdxlight_ftp_server
2.8
xlightftpdxlight_ftp_server
2.24
xlightftpdxlight_ftp_server
2.27
xlightftpdxlight_ftp_server
2.40
xlightftpdxlight_ftp_server
2.60
xlightftpdxlight_ftp_server
2.70
xlightftpdxlight_ftp_server
2.72
xlightftpdxlight_ftp_server
2.82
xlightftpdxlight_ftp_server
2.83
xlightftpdxlight_ftp_server
2.85
xlightftpdxlight_ftp_server
2.86
xlightftpdxlight_ftp_server
2.706
xlightftpdxlight_ftp_server
2.835
xlightftpdxlight_ftp_server
2.861
xlightftpdxlight_ftp_server
3.0
xlightftpdxlight_ftp_server
3.0.5
xlightftpdxlight_ftp_server
3.1
xlightftpdxlight_ftp_server
3.1.1
xlightftpdxlight_ftp_server
3.1.5
xlightftpdxlight_ftp_server
3.1.6
𝑥
= Vulnerable software versions