Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xm7r-423x-5463

Опубликовано: 20 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed between November 28 and December 2, 2010. The backdoor implements a hidden FTP command trigger that, when invoked, causes the server to execute arbitrary shell commands with root privileges. This allows remote, unauthenticated attackers to run any OS command on the FTP server host.

A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed between November 28 and December 2, 2010. The backdoor implements a hidden FTP command trigger that, when invoked, causes the server to execute arbitrary shell commands with root privileges. This allows remote, unauthenticated attackers to run any OS command on the FTP server host.

EPSS

Процентиль: 99%
0.85079
Высокий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-912

Связанные уязвимости

CVSS3: 9.8
nvd
6 месяцев назад

A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed between November 28 and December 2, 2010. The backdoor implements a hidden FTP command trigger that, when invoked, causes the server to execute arbitrary shell commands with root privileges. This allows remote, unauthenticated attackers to run any OS command on the FTP server host.

EPSS

Процентиль: 99%
0.85079
Высокий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-912