CVE

Id
42230  
CVE No.
CVE-2009-4795  
Status
Candidate  
Description
Multiple SQL injection vulnerabilities in Xlight FTP Server before 3.2.1, when ODBC authentication is enabled, allow remote attackers to execute arbitrary SQL commands via the (1) USER (aka username) or (2) PASS (aka password) command.  
Phase
Assigned (20100422)  
Votes
None (candidate not yet proposed)  
Comments