Xlight FTP Server Authentication SQL Injection

This script is Copyright (C) 2009-2013 Tenable Network Security, Inc.


Synopsis :

The remote FTP server is prone to a SQL injection attack.

Description :

The version of Xlight FTP installed on the remote host is vulnerable to
a SQL injection attack during login. This allows an attacker to execute
arbitrary SQL commands in the context of the FTP server.

Installations that are not using external ODBC authentication are not
affected by this vulnerability.

See also :

http://www.xlightftpd.com/whatsnew.htm

Solution :

Upgrade to version 3.2.1 or later.

Risk factor :

High / CVSS Base Score : 7.5
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVSS Temporal Score : 6.2
(CVSS2#E:F/RL:OF/RC:C)
Public Exploit Available : true

Family: FTP

Nessus Plugin ID: 36051 (ftp_xlight_sql_injection.nasl)

Bugtraq ID: 34288

CVE ID: CVE-2009-4795