CVE-2010-20103
Last modified
CVE-2010-20103 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed between November 28 and December 2, 2010. The backdoor implements a hidden FTP command trigger that, when invoked, causes the server to execute arbitrary shell commands with root privileges. EPSS estimates a 4.75% chance of exploitation in the next 30 days.
Description
A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed between November 28 and December 2, 2010. The backdoor implements a hidden FTP command trigger that, when invoked, causes the server to execute arbitrary shell commands with root privileges. This allows remote, unauthenticated attackers to run any OS command on the FTP server host.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Proftpd | Proftpd | 1.3.3 | C |
References
- http://www.proftpd.org/Product
- https://www.exploit-db.com/exploits/15662Exploit, VDB Entry
- https://www.exploit-db.com/exploits/16921Exploit, VDB Entry
- https://www.vulncheck.com/advisories/proftpd-backdoor-command-executionThird Party Advisory
- https://www.exploit-db.com/exploits/15662Exploit, VDB Entry
- https://www.exploit-db.com/exploits/16921Exploit, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2010-20103?
How severe is CVE-2010-20103?
How do I fix CVE-2010-20103?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2010
- CVE-2010-20059FreeNAS 0.7.2 prior to revision 5543 includes an unauthentic…9.3
- CVE-2010-2006Directory traversal vulnerability in op/op.Login.php in Leto…
- CVE-2010-2007Multiple cross-site request forgery (CSRF) vulnerabilities i…
- CVE-2010-2008MySQL before 5.1.48 allows remote authenticated users with a…
- CVE-2010-2009Stack-based buffer overflow in the media library in BS.Globa…
- CVE-2010-2010Multiple cross-site scripting (XSS) vulnerabilities in the C…
- CVE-2010-20107A stack-based buffer overflow exists in FTP Synchronizer Pro…8.5
- CVE-2010-20108FTPPad <= 1.2.0 contains a stack-based buffer overflow vulne…8.4
- CVE-2010-20109Barracuda products, confirmed in Spam & Virus Firewall, SSL …8.7
- CVE-2010-2011Microsoft Dynamics GP uses a substitution cipher to encrypt …
- CVE-2010-20110Rejected reason: This CVE has the been REJECTED and will not…
- CVE-2010-20111Digital Music Pad v8.2.3.3.4 contains a stack-based buffer o…8.4
Are you affected by CVE-2010-20103?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
