Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Xlight FTP Server Authentication SQL Injection

High

Synopsis

The remote host is vulnerable to a SQL Injection attack.

Description

The version of Xlight FTP installed on the remote host is vulnerable to a SQL injection attack during login. This allows an attacker to execute arbitrary SQL commands in the context of the FTP server. Installations that are not using external ODBC authentication are not affected by this vulnerability.

Solution

Upgrade to version 3.2.1 or higher.