CVE-2020-9273
HIGHProFTPD 1.3.7 - Use-After-Free in Memory Pool via Data Transfer Channel Interruption
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2020-9273. PoCs published by lockedbyte, dukptkey, ptef.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2020-9273, a use-after-free vulnerability in ProFTPd leading to remote code execution. The exploit leverages memory leaks via `/proc/self/maps` and hijacks control flow through pool corruption to achieve RCE.
Description
In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution.
Exploits (3)
This repository contains a functional exploit for CVE-2020-9273, a use-after-free vulnerability in ProFTPd leading to remote code execution. The exploit leverages memory leaks via `/proc/self/maps` and hijacks control flow through pool corruption to achieve RCE.
This repository contains functional exploit code for CVE-2020-9273, a use-after-free vulnerability in ProFTPD. The exploit demonstrates remote code execution by manipulating memory structures and includes detailed technical commentary on the exploitation process.
This repository contains functional exploit code for CVE-2020-9273, a heap use-after-free vulnerability in ProFTPd. The exploit includes a demo and a reliable version, both demonstrating remote code execution via crafted FTP commands and shellcode.
References (12)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H