Vulnerability record · CVE-2009-0542 · published 12 February 2009
CVE-2009-0542: ProFTPD mod_sql SQL injection via percent character in username
PProftpd Project · Proftpd
ProFTPD Server 1.3.1 through 1.3.2rc2 contains a SQL injection flaw in mod_sql: a "%" character in the username introduces a single quote during variable substitution, letting the input break out of the SQL statement. Because the username is attacker-controlled and processed before authentication completes, this is remotely reachable and can corrupt or subvert the backend authentication database.
Description
SQL injection vulnerability in ProFTPD Server 1.3.1 through 1.3.2rc2 allows remote attackers to execute arbitrary SQL commands via a "%" (percent) character in the username, which introduces a "'" (single quote) character during variable substitution by mod_sql.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityUnauthenticated remote SQL injection with a public exploit and very high EPSS probability, though the affected ProFTPD versions are long outdated.
What it is
ProFTPD Server 1.3.1 through 1.3.2rc2 contains a SQL injection flaw in mod_sql: a "%" character in the username introduces a single quote during variable substitution, letting the input break out of the SQL statement. Because the username is attacker-controlled and processed before authentication completes, this is remotely reachable and can corrupt or subvert the backend authentication database.
Impact
An unauthenticated remote attacker can execute arbitrary SQL commands against the database backing ProFTPD authentication, potentially reading or modifying credentials and other stored data.
Attack surface
Reached over the network through the FTP service by supplying a crafted username containing a percent character; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV, but EPSS is 0.77398 (99.5th percentile) and a public Exploit-DB entry (8037) exists, indicating mature public exploitation.
What to do
- Upgrade ProFTPD to a version after 1.3.2rc2 that contains the mod_sql fix; apply the vendor or distribution patch if staying on the current branch.
- If mod_sql is not required, disable it and avoid SQL-backed authentication.
- Restrict FTP exposure to trusted networks and enforce strong authentication to reduce reachable attack surface.
- Apply the Debian, Gentoo or Mandriva security advisories referenced for this CVE if running those distributions.
Detection
- Review ProFTPD and mod_sql logs for usernames containing "%" or quote characters, especially repeated failed logins.
- Enable and monitor database query logging for malformed or unexpected SQL originating from the FTP authentication path.
- Alert on FTP authentication attempts with anomalous username patterns or unusually high failure rates from single sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2009-0542 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-0542), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.