← Vulnerability feed

Vulnerability record · CVE-2009-0542 · published 12 February 2009

CVE-2009-0542: ProFTPD mod_sql SQL injection via percent character in username

PProftpd Project · Proftpd

ProFTPD Server 1.3.1 through 1.3.2rc2 contains a SQL injection flaw in mod_sql: a "%" character in the username introduces a single quote during variable substitution, letting the input break out of the SQL statement. Because the username is attacker-controlled and processed before authentication completes, this is remotely reachable and can corrupt or subvert the backend authentication database.

7.5 CVSS 2.0 High EPSS 74% · top 0.5% CWE-89 · SQL injection
7.5CVSS 2.0 base score
74%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
26References
16 Jun 2026Last modified by NVD

Description

SQL injection vulnerability in ProFTPD Server 1.3.1 through 1.3.2rc2 allows remote attackers to execute arbitrary SQL commands via a "%" (percent) character in the username, which introduces a "'" (single quote) character during variable substitution by mod_sql.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityUnauthenticated remote SQL injection with a public exploit and very high EPSS probability, though the affected ProFTPD versions are long outdated.

What it is

ProFTPD Server 1.3.1 through 1.3.2rc2 contains a SQL injection flaw in mod_sql: a "%" character in the username introduces a single quote during variable substitution, letting the input break out of the SQL statement. Because the username is attacker-controlled and processed before authentication completes, this is remotely reachable and can corrupt or subvert the backend authentication database.

Impact

An unauthenticated remote attacker can execute arbitrary SQL commands against the database backing ProFTPD authentication, potentially reading or modifying credentials and other stored data.

Attack surface

Reached over the network through the FTP service by supplying a crafted username containing a percent character; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV, but EPSS is 0.77398 (99.5th percentile) and a public Exploit-DB entry (8037) exists, indicating mature public exploitation.

What to do

  • Upgrade ProFTPD to a version after 1.3.2rc2 that contains the mod_sql fix; apply the vendor or distribution patch if staying on the current branch.
  • If mod_sql is not required, disable it and avoid SQL-backed authentication.
  • Restrict FTP exposure to trusted networks and enforce strong authentication to reduce reachable attack surface.
  • Apply the Debian, Gentoo or Mandriva security advisories referenced for this CVE if running those distributions.

Detection

  • Review ProFTPD and mod_sql logs for usernames containing "%" or quote characters, especially repeated failed logins.
  • Enable and monitor database query logging for malformed or unexpected SQL originating from the FTP authentication path.
  • Alert on FTP authentication attempts with anomalous username patterns or unusually high failure rates from single sources.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2009-0542 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2006-5815ProFTPD sreplace stack buffer overflow allows remote code executionProFTPD 1.3.0 and earlier contains a stack-based buffer overflow in the sreplace function. A remote attacker, probably authenticated, can trigger the…EPSS 74%analysed10.0CVE-2003-0500Proftpd project proftpd vulnerabilitySQL injection vulnerability in the PostgreSQL authentication module (mod_sql_postgres) for ProFTPD before 1.2.9rc1 allows remote attackers to execute…EPSS 18%10.0CVE-1999-0911Proftpd project proftpd vulnerabilityBuffer overflow in ProFTPD, wu-ftpd, and beroftpd allows remote attackers to gain root access via a series of MKD and CWD commands that create nested…EPSS 38%10.0CVE-1999-0368Proftpd project proftpd vulnerabilityBuffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.EPSS 40%9.0CVE-2003-0831ProFTPD ASCII mode newline handling buffer overflow allows remote code executionProFTPD 1.2.7 through 1.2.9rc2 fails to properly translate newline characters when transferring files in ASCII mode, resulting in a buffer overflow. …EPSS 58%analysed7.5CVE-2006-6170Proftpd project proftpd vulnerabilityBuffer overflow in the tls_x509_name_oneline function in the mod_tls module, as used in ProFTPD 1.3.0a and earlier, and possibly other products, allo…EPSS 17%7.5CVE-2006-6171Proftpd project proftpd vulnerabilityProFTPD 1.3.0a and earlier does not properly set the buffer size limit when CommandBufferSize is specified in the configuration file, which leads to …EPSS 9.7%7.5CVE-2005-4816Proftpd project proftpd vulnerabilityBuffer overflow in mod_radius in ProFTPD before 1.3.0rc2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary …EPSS 13%

Source: NIST National Vulnerability Database (record CVE-2009-0542), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.