Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-1999-0911

6 documents5 sources
Severity
10.0CRITICAL
EPSS
21.3%
top 4.32%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedAug 27
Latest updateApr 30

Description

Buffer overflow in ProFTPD, wu-ftpd, and beroftpd allows remote attackers to gain root access via a series of MKD and CWD commands that create nested directories.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages1 packages

NVDproftpd_project/proftpd5 versions+4

🔴Vulnerability Details

2
GHSA
GHSA-7mmm-q9r4-mm4v: Buffer overflow in ProFTPD, wu-ftpd, and beroftpd allows remote attackers to gain root access via a series of MKD and CWD commands that create nested2022-04-30
CVEList
CVE-1999-0911: Buffer overflow in ProFTPD, wu-ftpd, and beroftpd allows remote attackers to gain root access via a series of MKD and CWD commands that create nested2000-02-04

💥Exploits & PoCs

2
Exploit-DB
ProFTPd 1.2 pre1/pre2/pre3/pre4/pre5 - Remote Buffer Overflow (2)1999-08-27
Exploit-DB
ProFTPd 1.2 pre1/pre2/pre3/pre4/pre5 - Remote Buffer Overflow (1)1999-08-17

🔍Detection Rules

1
Suricata
GPL FTP MKD overflow attempt2010-09-23