| Severity : |
Medium
|
| Published : |
2011-02-01
|
| Modified : |
2011-02-17
|
| Base Score : |
6.8
|
| Details : |
Heap-based buffer overflow in the sql_prepare_where function (contrib/mod_sql.c) in ProFTPD before 1.3.3d, when mod_sql is enabled, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted username containing substitution tags, which are not properly handled during construction of an SQL query.
|
| Product/Version : |
Carrier Grade CGE 5.1
|
|