CVE-2009-0543

Publication date

2009-02-12 16:00:00

Family

mitre

State

PUBLISHED

Description

ProFTPD Server 1.3.1, with NLS support enabled, allows remote attackers to bypass SQL injection protection mechanisms via invalid, encoded multibyte characters, which are not properly handled in (1) mod_sql_mysql and (2) mod_sql_postgres.