ProFTPD Server 1.3.1, with NLS support enabled, allows remote attackers to bypass SQL injection protection mechanisms via invalid, encoded multibyte characters, which are not properly handled in (1) modsqlmysql and (2) modsqlpostgres.
{ "urgency": "medium" }