PurePostPro Arbitrary SQL Command...

- AV AC AU C I A
发布: 2001-12-19
修订: 2025-04-13

PurePostPro is a freely available, open source script add-on to the ProFTPD ftp server. It was written and is maintained by Peter Garner. A user uploading a file to a PureFTPD server running PurePostPro may inject or modify arbitrary SQL commands through malicious file names. By uploading a file with a name containing quotes, it is possible for the user to escape the current SQL query to modify logic of the query.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息