CVE-2011-2523

CRITICAL NUCLEI

Vsftpd - OS Command Injection

Title source: rule

Description

vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.

Exploits (38)

nomisec WORKING POC 15 stars
by padsalatushal · poc
https://github.com/padsalatushal/CVE-2011-2523
nomisec WORKING POC 6 stars
by Lynk4 · poc
https://github.com/Lynk4/CVE-2011-2523
nomisec WORKING POC 4 stars
by 4m3rr0r · poc
https://github.com/4m3rr0r/CVE-2011-2523-poc
nomisec WORKING POC 3 stars
by nobodyatall648 · poc
https://github.com/nobodyatall648/CVE-2011-2523
nomisec WORKING POC 3 stars
by BolivarJ · poc
https://github.com/BolivarJ/CVE-2011-2523
nomisec WORKING POC 3 stars
by NullBrunk · poc
https://github.com/NullBrunk/CVE-2011-2523
nomisec WORKING POC 2 stars
by MFernstrom · poc
https://github.com/MFernstrom/OffensivePascal-CVE-2011-2523
nomisec WORKING POC 2 stars
by Gill-Singh-A · poc
https://github.com/Gill-Singh-A/vsFTP-2.3.4-Remote-Root-Shell-Exploit
nomisec WORKING POC 2 stars
by cowsecurity · poc
https://github.com/cowsecurity/CVE-2011-2523
nomisec WORKING POC 1 stars
by cybermads · poc
https://github.com/cybermads/CVE-2011-2523
nomisec WRITEUP 1 stars
by vedpakhare · poc
https://github.com/vedpakhare/vsftpd-234-vuln-report
nomisec WORKING POC 1 stars
by krill-x7 · poc
https://github.com/krill-x7/CVE-2011-2523
nomisec WORKING POC
by Gr4ykt · poc
https://github.com/Gr4ykt/CVE-2011-2523
nomisec WRITEUP
by yagnikkrish · poc
https://github.com/yagnikkrish/metasploitable-penetration-testing-lab
nomisec WORKING POC
by 0xB0y426 · poc
https://github.com/0xB0y426/CVE-2011-2523-PoC
nomisec SUSPICIOUS
by AnugiArrawwala · poc
https://github.com/AnugiArrawwala/CVE-Research
nomisec WORKING POC
by avivyap · poc
https://github.com/avivyap/CVE-2011-2523
nomisec WRITEUP
by Mirza-22144 · poc
https://github.com/Mirza-22144/Vulnerability-Assessment-Exploitation-Lab
nomisec WORKING POC
by tshaq17 · poc
https://github.com/tshaq17/vsftpd-2.3.4---Backdoor-Command-Execution
nomisec WRITEUP
by Efehamzaa · poc
https://github.com/Efehamzaa/Metasploit-Red-Pentest-Lab
nomisec WRITEUP
by KlyneZyro · poc
https://github.com/KlyneZyro/Metasploitable2-VAPT-Report
nomisec WORKING POC
by HerculesRD · poc
https://github.com/HerculesRD/vsftpd2.3.4PyExploit
nomisec WRITEUP
by JohanMV · poc
https://github.com/JohanMV/explotacion-vsftpd-nmap_Laboratorio_1
nomisec TROJAN
by vaishnavucv · poc
https://github.com/vaishnavucv/CVE-2011-2523
nomisec WORKING POC
by lghost256 · poc
https://github.com/lghost256/vsftpd234-exploit
nomisec WRITEUP
by seerat-fatima21 · poc
https://github.com/seerat-fatima21/vsftpd-exploit
nomisec WRITEUP
by XiangSi-Howard · poc
https://github.com/XiangSi-Howard/CTF---CVE-2011-2523
nomisec WORKING POC
by Shubham-2k1 · poc
https://github.com/Shubham-2k1/Exploit-CVE-2011-2523
nomisec WORKING POC
by sug4r-wr41th · poc
https://github.com/sug4r-wr41th/CVE-2011-2523
nomisec WORKING POC
by 0xSojalSec · poc
https://github.com/0xSojalSec/-CVE-2011-2523
nomisec WORKING POC
by Tenor-Z · poc
https://github.com/Tenor-Z/SmileySploit
nomisec WORKING POC
by 0xSojalSec · poc
https://github.com/0xSojalSec/CVE-2011-2523
nomisec WORKING POC
by Lychi3 · poc
https://github.com/Lychi3/vsftpd-backdoor
nomisec WORKING POC
by hklabCR · poc
https://github.com/hklabCR/CVE-2011-2523
metasploit WORKING POC EXCELLENT
by hdm, MC · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/ftp/vsftpd_234_backdoor.rb
exploitdb WORKING POC VERIFIED
by HerculesRD · pythonremoteunix
https://www.exploit-db.com/exploits/49757
exploitdb WORKING POC VERIFIED
by Metasploit · rubyremoteunix
https://www.exploit-db.com/exploits/17491

Nuclei Templates (1)

VSFTPD 2.3.4 - Backdoor Command Execution
CRITICALVERIFIEDby pussycat0x
Shodan: product:"vsftpd"

Scores

CVSS v3 9.8
EPSS 0.9426
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-78
Status published

Affected Products (4)

vsftpd_project/vsftpd
debian/debian_linux
debian/debian_linux
debian/debian_linux

Timeline

Published Nov 27, 2019
Tracked Since Feb 18, 2026