Vulnerabilities > Proftpd > Medium

DATE CVE VULNERABILITY TITLE RISK
2009-10-28 CVE-2009-3639 Cryptographic Issues vulnerability in Proftpd
The mod_tls module in ProFTPD before 1.3.2b, and 1.3.3 before 1.3.3rc2, when the dNSNameRequired TLS option is enabled, does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 client certificate, which allows remote attackers to bypass intended client-hostname restrictions via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
network
proftpd CWE-310
5.8
2009-02-12 CVE-2009-0543 SQL Injection vulnerability in Proftpd 1.3.1
ProFTPD Server 1.3.1, with NLS support enabled, allows remote attackers to bypass SQL injection protection mechanisms via invalid, encoded multibyte characters, which are not properly handled in (1) mod_sql_mysql and (2) mod_sql_postgres.
network
proftpd CWE-89
6.8