PurePostPro Arbitrary SQL Command Injection Vulnerability
BID:3719
Info
PurePostPro Arbitrary SQL Command Injection Vulnerability
| Bugtraq ID: | 3719 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 19 2001 12:00AM |
| Updated: | Dec 19 2001 12:00AM |
| Credit: | This vulnerability was announced by Peter Garner <[email protected]> on December 12, 2001. |
| Vulnerable: |
PurePostPro PurePostPro 1.2 PurePostPro PurePostPro 1.1 PurePostPro PurePostPro 1.0 |
| Not Vulnerable: |
PurePostPro PurePostPro 1.3 |
Discussion
PurePostPro Arbitrary SQL Command Injection Vulnerability
PurePostPro is a freely available, open source script add-on to the ProFTPD ftp server. It was written and is maintained by Peter Garner.
A user uploading a file to a PureFTPD server running PurePostPro may inject or modify arbitrary SQL commands through malicious file names. By uploading a file with a name containing quotes, it is possible for the user to escape the current SQL query to modify logic of the query.
PurePostPro is a freely available, open source script add-on to the ProFTPD ftp server. It was written and is maintained by Peter Garner.
A user uploading a file to a PureFTPD server running PurePostPro may inject or modify arbitrary SQL commands through malicious file names. By uploading a file with a name containing quotes, it is possible for the user to escape the current SQL query to modify logic of the query.
Exploit / POC
PurePostPro Arbitrary SQL Command Injection Vulnerability
No exploit is required for this vulnerability.
No exploit is required for this vulnerability.
Solution / Fix
PurePostPro Arbitrary SQL Command Injection Vulnerability
Solution:
Upgrade available:
PurePostPro PurePostPro 1.0
PurePostPro PurePostPro 1.1
PurePostPro PurePostPro 1.2
Solution:
Upgrade available:
PurePostPro PurePostPro 1.0
-
PurePostPro PurePostPro 1.3
http://www.mildewhall.demon.co.uk/purepostpro/PurePostPro.tar
PurePostPro PurePostPro 1.1
-
PurePostPro PurePostPro 1.3
http://www.mildewhall.demon.co.uk/purepostpro/PurePostPro.tar
PurePostPro PurePostPro 1.2
-
PurePostPro PurePostPro 1.3
http://www.mildewhall.demon.co.uk/purepostpro/PurePostPro.tar
References
PurePostPro Arbitrary SQL Command Injection Vulnerability
References:
References:
- PurePostPro Homepage (PurePostPro)