CVE-2010-4652
Heap-based buffer overflow in the sql_prepare_where function (contrib/mod_sql.c) in ProFTPD before 1.3.3d, when mod_sql
Heap-based buffer overflow in the sql_prepare_where function (contrib/mod_sql.c) in ProFTPD before 1.3.3d, when mod_sql is enabled, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted username containing substitution tags, which are not properly handled during construction of an SQL query.
MEDIUM · CVSS 6.8
EPSS 0.05491
Schedule remediation
- EPSS percentile: top 10% of all CVEs by exploitation likelihood
- Public exploit or PoC is available
Sigma rules0
YARA rules0