目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2011-2523— vsftpd 操作系统命令注入漏洞

一分钟漏洞结论

影响对象
vsftpd vsftpd
利用判断
存在公开或 AI PoC,应优先验证
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

vsftpd是一款用于类Unix系统的FTP(文件传输协议)服务器。 vsftpd 2.3.4版本(2011年6月30日至2011年7月3日期间下载)中存在安全漏洞,该漏洞源于软件中存在可以打开shell的后门。攻击者可利用该漏洞执行命令。

AI 预测 10.0 利用难度: 极易 EPSS 96.18% · P100

公开利用映射 3

获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2011-2523 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
N/A
来源: CVE Program / CVE List V5
Vulnerability Description
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
vsftpd 操作系统命令注入漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
vsftpd是一款用于类Unix系统的FTP(文件传输协议)服务器。 vsftpd 2.3.4版本(2011年6月30日至2011年7月3日期间下载)中存在安全漏洞,该漏洞源于软件中存在可以打开shell的后门。攻击者可利用该漏洞执行命令。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

神龙十问 — AI 深度分析

十问解析:根本原因、利用方式、修复建议、紧迫性。摘要免费,完整版需登录。

受影响产品

厂商 产品 影响版本 CPE 订阅
vsftpd vsftpd 2.3.4 downloaded between 20110630 and 20110703 -

二、漏洞 CVE-2011-2523 的公开POC

# POC 描述 源链接 神龙链接
1 An exploit to get root in vsftpd 2.3.4 (CVE-2011-2523) written in python https://github.com/HerculesRD/vsftpd2.3.4PyExploit POC详情
2 vsftpd 2.3.4 Backdoor Exploit https://github.com/nobodyatall648/CVE-2011-2523 POC详情
3 https://www.exploit-db.com/exploits/49757 https://github.com/Gr4ykt/CVE-2011-2523 POC详情
4 Python exploit for vsftpd 2.3.4 - Backdoor Command Execution https://github.com/padsalatushal/CVE-2011-2523 POC详情
5 FreePascal implementation of the vsFTPD 2.3.4 CVE-2011-2523 https://github.com/MFernstrom/OffensivePascal-CVE-2011-2523 POC详情
6 Python exploit for CVE-2011-2523 (VSFTPD 2.3.4 Backdoor Command Execution) https://github.com/0xSojalSec/-CVE-2011-2523 POC详情
7 Python exploit for CVE-2011-2523 (VSFTPD 2.3.4 Backdoor Command Execution) https://github.com/0xSojalSec/CVE-2011-2523 POC详情
8 None https://github.com/XiangSi-Howard/CTF---CVE-2011-2523 POC详情
9 CVE-2011-2523 exploit https://github.com/0xFTW/CVE-2011-2523 POC详情
10 Python exploit for vsftpd 2.3.4 - Backdoor Command Execution https://github.com/Lynk4/CVE-2011-2523 POC详情
11 Python exploit for vsftpd 2.3.4 - Backdoor Command Execution https://github.com/vaishnavucv/CVE-2011-2523 POC详情
12 A tool that exploits the CVE-2011-2523 vulnerability. https://github.com/chleba124/vsftpd-exploit POC详情
13 Python exploit for CVE-2011-2523 (VSFTPD 2.3.4 Backdoor Command Execution) https://github.com/4m3rr0r/CVE-2011-2523-poc POC详情
14 CVE-2011-2523 exploit https://github.com/cowsecurity/CVE-2011-2523 POC详情
15 None https://github.com/Shubham-2k1/Exploit-CVE-2011-2523 POC详情
16 A basic script that exploits CVE-2011-2523 https://github.com/Tenor-Z/SmileySploit POC详情
17 vsFTPd 2.3.4 Remote Code Execution (CVE-2011-2523) PoC https://github.com/sug4r-wr41th/CVE-2011-2523 POC详情
18 POC para CVE-2011-2523 https://github.com/Fatalitysec/vsftpd_2.3.4_Backdoor POC详情
19 A Simple Python Program that uses gets a Remote Root Shell on the Target Device by exploiting a Vulnerability (CVE-2011-2523) present in vsFTP 2.3.4 https://github.com/Gill-Singh-A/vsFTP-2.3.4-Remote-Root-Shell-Exploit POC详情
20 This tool exploits a well-known backdoor vulnerability found in vsFTPd version 2.3.4 (CVE-2011-2523) https://github.com/everythingBlackkk/vsFTPd-Backdoor-Exploit-CVE-2011-2523- POC详情
21 PoC CVE-2011-2523 https://github.com/Uno13x/CVE-2011-2523-PoC POC详情
22 PoC CVE-2011-2523 https://github.com/R4idB0Y/CVE-2011-2523-PoC POC详情
23 PoC CVE-2011-2523 https://github.com/0xB0y426/CVE-2011-2523-PoC POC详情
24 VsFTPd 2.3.4 Backdoor Command Execution https://github.com/NullBrunk/CVE-2011-2523 POC详情
25 CVE-2011-2523 vsftpd 2.3.4 exploit https://github.com/Lychi3/vsftpd-backdoor POC详情
26 Vulnerability assessment and exploitation of vsftpd 2.3.4 (CVE-2011-2523) using Metasploit. Full report and proof of root access included. https://github.com/vedpakhare/vsftpd-234-vuln-report POC详情
27 None https://github.com/madanokr001/CVE-2011-2523 POC详情
28 VSFTPD v2.3.4 had a serious backdoor vulnerability allowing attackers to execute arbitrary commands on the server with root-level access. The backdoor was triggered by a specific string of characters in a user login request, which allowed attackers to execute any command they wanted. https://github.com/projectdiscovery/nuclei-templates/blob/main/network/cves/2011/CVE-2011-2523.yaml POC详情
29 Laboratorio técnico de ciberseguridad donde se realiza reconocimiento de red con Nmap y explotación de la vulnerabilidad CVE-2011-2523 (vsftpd 2.3.4) mediante Metasploit Framework. Proyecto académico orientado a demostrar habilidades en análisis de vulnerabilidades, uso de herramientas de pentesting y reporte técnico. https://github.com/JohanMV/explotacion-vsftpd-nmap_Laboratorio_1 POC详情
30 Exploit for CVE-2011-2523. https://github.com/lghost256/vsftpd234-exploit POC详情
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2011-2523 的情报信息

登录查看更多情报信息。

CVE-2011-2523 厂商安全公告 (2)

CVE-2011-2523 公开利用代码 (1)

CVE-2011-2523 邮件列表归档 (1)

CVE-2011-2523 其他参考 (1)

V. Comments for CVE-2011-2523

匿名用户
2026-01-15 06:08:57

Zaproxy alias impedit expedita quisquam pariatur exercitationem. Nemo rerum eveniet dolores rem quia dignissimos.


发表评论