PT-2010-5128 · Proftpd · Proftpd

Florian Weimer

·

Publicado

2010-11-09

·

Atualizado

2011-09-15

·

CVE-2010-3867

CVSS v2.0

7.1

Alta

VetorAV:N/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ProFTPD versions prior to 1.3.3c
Description The issue allows remote authenticated users to perform unauthorized actions such as creating directories, deleting directories, creating symlinks, and modifying file timestamps. This is achieved through directory traversal sequences in specific commands, including SITE MKDIR, SITE RMDIR, SITE SYMLINK, and SITE UTIME commands.
Recommendations For versions prior to 1.3.3c, update to version 1.3.3c or later to resolve the issue.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-3867
DSA-2191-1

Produtos afetados

Proftpd