PonVFTP suffers from a remote SQL injection vulnerability that allows for authentication bypass. Once this is achieved, administrative privileges can be leveraged to upload a shell.
957de70f6881fa7d95c9f5ef49ab0ab8
© 2012 Packet Storm. All rights reserved.