CVE-2006-5815

Proftpd < 1.3.0 - Memory Corruption

Title source: rule

Description

Stack-based buffer overflow in the sreplace function in ProFTPD 1.3.0 and earlier allows remote attackers, probably authenticated, to cause a denial of service and execute arbitrary code, as demonstrated by vd_proftpd.pm, a "ProFTPD remote exploit."

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotelinux
https://www.exploit-db.com/exploits/16852
exploitdb WORKING POC VERIFIED
by Evgeny Legerov · remotelinux
https://www.exploit-db.com/exploits/2856
metasploit WORKING POC GREAT
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/ftp/proftp_sreplace.rb

Scores

EPSS 0.7339
EPSS Percentile 98.8%

Details

CWE
CWE-119
Status published
Products (1)
proftpd_project/proftpd < 1.3.0
Published Nov 08, 2006
Tracked Since Feb 18, 2026