PT-2015-1244 · Proftpd+1 · Proftpd+1
R-73En
·
Publicado
2015-05-18
·
Atualizado
2026-03-10
·
CVE-2015-3306
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
ProFTPD version 1.3.5
Description
The issue allows remote attackers to read and write to arbitrary files. This is achieved via the site cpfr and site cpto commands, which are part of the mod copy module in the ProFTPD FTP server.
Recommendations
For ProFTPD version 1.3.5, consider disabling the mod copy module as a temporary workaround until a patch is available. Restrict access to the site cpfr and site cpto commands to minimize the risk of exploitation.
Exploit
Correção
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Proftpd