CVE-2015-3306
65Vexday Risk Score
Corrija em breve. Ela tem exploit funcional público.
ssvc Attendepss 97%
da publicação à arma0 dias
Publicada no NVD18 de mai.
1ª PoC13 de abr.
metasploit22 de abr.
probabilidade de exploração
97%top 1% das CVEs
exploração observada
nãonenhuma fonte reporta
28 exploit(s) público(s)
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
Produtos afetados
n/a · n/aPoCs públicas encontradas — 28✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/37262exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/49908exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/36742exploitdbwww.exploit-db.com/exploits/36803não verificadogithubgithub.com/t0kx/exploit-CVE-2015-3306★ 150githubgithub.com/nootropics/propane★ 2githubgithub.com/davidtavarez/CVE-2015-3306★ 1githubgithub.com/bcononugbor-source/OpenVAS-Vulnerability-Analysis-Incident-Response-Report★ 1githubgithub.com/jptr218/proftpd_bypass★ 1githubgithub.com/0xm4ud/ProFTPD_CVE-2015-3306★ 1githubgithub.com/cd6629/CVE-2015-3306-Python-PoC★ 1githubgithub.com/cybersensei-EH/hackviser_labs_CVE-2015-3306★ 1githubgithub.com/xyk0x/cpx_proftpd★ 1githubgithub.com/cdedmondson/Modified-CVE-2015-3306-Exploit★ 0githubgithub.com/cved-sources/cve-2015-3306★ 0githubgithub.com/hackarada/cve-2015-3306★ 0githubgithub.com/JoseLRC97/ProFTPd-1.3.5-mod_copy-Remote-Command-Execution★ 0githubgithub.com/Z3R0space/CVE-2015-3306★ 0githubgithub.com/donmedfor/CVE-2015-3306★ 0githubgithub.com/netw0rk7/CVE-2015-3306-Home-Lab★ 0githubgithub.com/canpilayda/proftpd-mod_copy-cve-2015-3306★ 0cve_referencewww.exploit-db.com/exploits/36742/não verificadocve_referencepacketstormsecurity.com/files/131555/ProFTPd-1.3.5-Remote-Command-Execution.htmlnão verificadocve_referencepacketstormsecurity.com/files/131505/ProFTPd-1.3.5-File-Copy.htmlnão verificadocve_referencepacketstormsecurity.com/files/162777/ProFTPd-1.3.5-Remote-Command-Execution.htmlnão verificadocve_referencepacketstormsecurity.com/files/132218/ProFTPD-1.3.5-Mod_Copy-Command-Execution.htmlnão verificadocve_referencepacketstormsecurity.com/files/131567/ProFTPd-CPFR-CPTO-Proof-Of-Concept.htmlnão verificadocve_referencewww.exploit-db.com/exploits/36803/não verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Referências
http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157053.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/157054.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/157581.htmlhttp://lists.opensuse.org/opensuse-updates/2015-06/msg00020.htmlhttp://packetstormsecurity.com/files/131505/ProFTPd-1.3.5-File-Copy.htmlhttp://packetstormsecurity.com/files/131555/ProFTPd-1.3.5-Remote-Command-Execution.htmlhttp://packetstormsecurity.com/files/131567/ProFTPd-CPFR-CPTO-Proof-Of-Concept.htmlhttp://packetstormsecurity.com/files/132218/ProFTPD-1.3.5-Mod_Copy-Command-Execution.htmlhttp://packetstormsecurity.com/files/162777/ProFTPd-1.3.5-Remote-Command-Execution.htmlhttps://www.exploit-db.com/exploits/36742/https://www.exploit-db.com/exploits/36803/http://www.debian.org/security/2015/dsa-3263