bugs.proftpd.orgConfirmation
http://bugs.proftpd.org/show_bug.cgi?id=3711 CVE-2011-4130
ProFTPD Response API Remote Code Execution
Record summary
CVE-2011-4130 has a selected CVSS score of 9.0.
Description
Use-after-free vulnerability in the Response API in ProFTPD before 1.3.3g allows remote authenticated users to execute arbitrary code via vectors involving an error that occurs after an FTP data transfer.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 20, 2017 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
proftpdBrowse proftpd / proftpd | VulnCheck | Version data not supplied | |
References
5proftpd.orgConfirmation
http://www.proftpd.org/docs/NEWS-1.3.3g 50631vdb entry
http://www.securityfocus.com/bid/50631 zerodayinitiative.com
http://www.zerodayinitiative.com/advisories/ZDI-11-328 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2011-4130