Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2011-1575 PoC — Pure-FTPd ftp_parser.c STARTTLS实现明文命令注入漏洞

Source
Associated Vulnerability
Title:Pure-FTPd ftp_parser.c STARTTLS实现明文命令注入漏洞 (CVE-2011-1575)
Description:Pure-FTPd是一款流行的FTP服务程序。 Pure-FTPd 1.0.30之前版本的ftp_parser.c中的STARTTLS实现不能正确限制I/O缓冲。中间人攻击者可以在TLS实现就位后,通过发送已处理的明文命令,向加密的FTP会话插入命令。
Description
Very simple script to test for cve 2011-1575
File Snapshot

[4.0K] /data/pocs/509027658d8e8f5eafa7dcc9e63fd3d447920a48 └── [ 62] cve-2011-1575.sh 0 directories, 1 file
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.