Proftpd

Proftpd

37 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.3%
  • Veröffentlicht 20.07.2026 14:22:29
  • Zuletzt bearbeitet 30.07.2026 17:18:19

ProFTPD before 1.3.9c and 1.3.10rc3 contains a signed integer overflow vulnerability in the mod_sftp module's SCP size-record parser that allows authenticated low-privilege attackers to bypass ASLR by sending a crafted file size value of UINT64_MAX, ...

  • EPSS 0.5%
  • Veröffentlicht 20.07.2026 14:22:03
  • Zuletzt bearbeitet 30.07.2026 17:19:14

ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allows authenticated low-privilege attackers to achieve arbitrary code execution by sending crafted SFTP packet fragments exceeding th...

  • EPSS 0.42%
  • Veröffentlicht 18.07.2026 19:30:32
  • Zuletzt bearbeitet 30.07.2026 18:00:47

ProFTPD mod_sftp contains a heap-based buffer overflow reachable by an authenticated SFTP user. The fxp_packet_read() function accepts the attacker-supplied 32-bit big-endian SFTP packet length without a minimum sanity check. A value of 0 causes an u...

  • EPSS 0.35%
  • Veröffentlicht 24.06.2026 13:21:42
  • Zuletzt bearbeitet 14.07.2026 21:16:46

ProFTPD through 1.3.9b and 1.3.10rc2 contains an access control bypass vulnerability that allows authenticated FTP users to circumvent Directory ACL restrictions by prefixing paths with /proc/self/root in the RNFR command handler. Attackers can explo...

  • EPSS 0.46%
  • Veröffentlicht 05.05.2026 20:16:39
  • Zuletzt bearbeitet 24.07.2026 20:10:00

In ProFTPD through 1.3.9a before 7666224, a SQL injection vulnerability in sqltab_fetch_clients_cb() in contrib/mod_wrap2_sql.c allows a remote attacker to inject arbitrary SQL commands via a crafted domain name that is accessed in a reverse DNS look...

Medienbericht Exploit
  • EPSS 4.28%
  • Veröffentlicht 28.04.2026 00:00:00
  • Zuletzt bearbeitet 24.07.2026 21:10:00

mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROGRAM).

Exploit
  • EPSS 0.56%
  • Veröffentlicht 21.01.2026 17:27:44
  • Zuletzt bearbeitet 15.04.2026 00:35:42

ProFTPD 1.3.7a contains a denial of service vulnerability that allows attackers to overwhelm the server by creating multiple simultaneous FTP connections. Attackers can repeatedly establish connections using threading to exhaust server connection lim...

Exploit
  • EPSS 5.09%
  • Veröffentlicht 20.08.2025 15:38:46
  • Zuletzt bearbeitet 15.07.2026 02:16:56

A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed between November 28 and December 2, 2010. The backdoor implements a hidden FTP command trigger that, when invoked, causes the server to execute arbitrary shel...

  • EPSS 1.17%
  • Veröffentlicht 06.02.2025 22:15:39
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Buffer Overflow vulnerability in Proftpd commit 4017eff8 allows a remote attacker to execute arbitrary code and can cause a Denial of Service (DoS) on the FTP service by sending a maliciously crafted message to the ProFTPD service port.

  • EPSS 2.2%
  • Veröffentlicht 29.11.2024 05:15:05
  • Zuletzt bearbeitet 15.04.2026 00:35:42

In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplemental groups from mod_sql.