Vulnerabilities > Proftpd > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2009-10-28 | CVE-2009-3639 | Cryptographic Issues vulnerability in Proftpd The mod_tls module in ProFTPD before 1.3.2b, and 1.3.3 before 1.3.3rc2, when the dNSNameRequired TLS option is enabled, does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 client certificate, which allows remote attackers to bypass intended client-hostname restrictions via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408. | 5.8 |
2009-02-12 | CVE-2009-0543 | SQL Injection vulnerability in Proftpd 1.3.1 ProFTPD Server 1.3.1, with NLS support enabled, allows remote attackers to bypass SQL injection protection mechanisms via invalid, encoded multibyte characters, which are not properly handled in (1) mod_sql_mysql and (2) mod_sql_postgres. | 6.8 |