CVE-2010-2620

Open-ftpd < 1.2 - Authentication Bypass

Title source: rule

Description

Open&Compact FTP Server (Open-FTPD) 1.2 and earlier allows remote attackers to bypass authentication by sending (1) LIST, (2) RETR, (3) STOR, or other commands without performing the required login steps first.

Exploits (4)

exploitdb WORKING POC VERIFIED
by Wireghoul · pythonremotewindows
https://www.exploit-db.com/exploits/27401
exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/27556
exploitdb WORKING POC VERIFIED
by Serge Gorbunov · pythonremotewindows
https://www.exploit-db.com/exploits/13932
metasploit WORKING POC EXCELLENT
by Serge Gorbunov, bcoles · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/ftp/open_ftpd_wbem.rb

Scores

EPSS 0.5567
EPSS Percentile 98.0%

Classification

CWE
CWE-287
Status draft

Affected Products (2)

open-ftpd/open-ftpd < 1.2
open-ftpd/open-ftpd

Timeline

Published Jul 02, 2010
Tracked Since Feb 18, 2026