10
CVSSv2

CVE-2006-5815

Published: 08/11/2006 Updated: 17/10/2018
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Stack-based buffer overflow in the sreplace function in ProFTPD 1.3.0 and previous versions allows remote attackers, probably authenticated, to cause a denial of service and execute arbitrary code, as demonstrated by vd_proftpd.pm, a "ProFTPD remote exploit."

Vulnerable Product Search on Vulmon Subscribe to Product

proftpd project proftpd

Vendor Advisories

Debian Bug report logs - #399070 CVE-2006-5815: remote code execution in ProFTPD Package: proftpd; Maintainer for proftpd is (unknown); Reported by: Modestas Vainius <geromanas@mailascom> Date: Fri, 17 Nov 2006 14:03:02 UTC Severity: grave Tags: security Found in versions proftpd-dfsg/130-12, 130-13, 1210-15sarge2 ...
Due to technical problems yesterday's proftpd update lacked a build for the amd64 architecture, which is now available For reference please find below the original advisory text: Several remote vulnerabilities have been discovered in the proftpd FTP daemon, which may lead to the execution of arbitrary code or denial of service The Common Vulnera ...

Exploits

A remotely exploitable stack overflow vulnerability has been found in ProFTPD server The vulnerability allows a remote authenticated attacker to gain root privileges Versions below 130a are affected Exploit included ...
# vd_proftpdpm - Metasploit module for ProFTPD stack overflow # # Copyright (c) 2006 Evgeny Legerov # # Permission to use, copy, modify, and distribute this software for any # purpose with or without fee is hereby granted, provided that the above # copyright notice and this permission notice appear in all copies # # THE SOFTWARE IS PROVIDED "AS I ...
## # $Id: proftp_sreplacerb 11526 2011-01-09 23:33:53Z jduck $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require 'msf/core' class ...