Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-48651 PoC — ProFTPD 安全漏洞

Source
Associated Vulnerability
Title:ProFTPD 安全漏洞 (CVE-2024-48651)
Description:ProFTPD是ProFTPD开源的一套可配置性强的开放源代码的FTP服务器软件。 ProFTPD 1.3.8b版本存在安全漏洞,该漏洞源于缺少来自mod_sql的补充组,补充组继承授予了对GID 0的意外访问权限。
Description
ProFTPD versions through 1.3.8b (before commit cec01cc) contain a vulnerability in the mod_sql module due to improper handling of supplemental groups. This flaw allows authenticated users without explicitly assigned supplemental groups to inherit root group privileges (GID 0), potentially granting unauthorized access to sensitive system resources.
File Snapshot

id: CVE-2024-48651 info: name: ProFTPD ≤ 1.3.8b - Privilege Escalation via mod_sql author: puss ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.