ProFTPD是ProFTPD开源的一套可配置性强的开放源代码的FTP服务器软件。 ProFTPD 1.3.3c版本存在安全漏洞,该漏洞源于源代码包中嵌入恶意后门,可能导致未经验证的攻击者以root权限执行任意命令。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ProFTPD Project | ProFTPD (Professional FTP Daemon) | 1.3.3c |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ProFTPD Project | ProFTPD (Professional FTP Daemon) | 1.3.3c | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | ProFTPD 1.3.3c contains a command injection backdoor caused by a hidden FTP command trigger in the source tarball, letting remote unauthenticated attackers execute arbitrary shell commands with root privileges. | https://github.com/projectdiscovery/nuclei-templates/blob/main/javascript/cves/CVE-2010-20103.yaml | POC Details |
| 2 | ProFTPD 1.3.3c contains a command injection backdoor caused by a hidden FTP command trigger in the source tarball, letting remote unauthenticated attackers execute arbitrary shell commands with root privileges. | https://github.com/projectdiscovery/nuclei-templates/blob/main/javascript/cves/2010/CVE-2010-20103.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet