Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2010-3867

Multiple directory traversal vulnerabilities in the mod_site_misc module in ProFTPD before 1.3.3c allow remote authenticated users to create directories, delete directories, create symlinks, and modify file timestamps via directory traversal sequences in a (1) SITE MKDIR, (2) SITE RMDIR, (3) SITE SYMLINK, or (4) SITE UTIME command.

  • Published: Nov 9, 2010
  • Updated: Apr 13, 2023
  • CVE: CVE-2010-3867
  • Severity: High
  • Exploit:

CVSS v2:

  • Severity: High
  • Score: 7.1
  • AV:N/AC:H/Au:S/C:C/I:C/A:C
Software From Fixed in
proftpd / proftpd 1.3.3-b 1.3.3-b.x
proftpd / proftpd 1.3.3-rc4 1.3.3-rc4.x
proftpd / proftpd 1.3.1-rc2 1.3.1-rc2.x
proftpd / proftpd 1.3.0-rc1 1.3.0-rc1.x
proftpd / proftpd 1.3.2-d 1.3.2-d.x
proftpd / proftpd 1.3.0-a 1.3.0-a.x
proftpd / proftpd 1.3.0-rc4 1.3.0-rc4.x
proftpd / proftpd 1.3.1-rc3 1.3.1-rc3.x
proftpd / proftpd 1.3.2-a 1.3.2-a.x
proftpd / proftpd 1.3.3-rc2 1.3.3-rc2.x
proftpd / proftpd 1.3.2-c 1.3.2-c.x
proftpd / proftpd 1.2.10 1.2.10.x
proftpd / proftpd 1.3.2-e 1.3.2-e.x
proftpd / proftpd 1.2.10-rc2 1.2.10-rc2.x
proftpd / proftpd 1.3.1 1.3.1.x
proftpd / proftpd 1.3.2 1.3.2.x
proftpd / proftpd 1.3.3-rc3 1.3.3-rc3.x
proftpd / proftpd 1.3.0 1.3.0.x
proftpd / proftpd 1.2.10-rc1 1.2.10-rc1.x
proftpd / proftpd 1.3.1-rc1 1.3.1-rc1.x
proftpd / proftpd 1.3.0-rc5 1.3.0-rc5.x
proftpd / proftpd 1.3.3-a 1.3.3-a.x
proftpd / proftpd 1.3.2-rc1 1.3.2-rc1.x
proftpd / proftpd 1.3.2-rc2 1.3.2-rc2.x
proftpd / proftpd 1.3.2-rc3 1.3.2-rc3.x
proftpd / proftpd 1.3.2-b 1.3.2-b.x
proftpd / proftpd 1.3.2-rc4 1.3.2-rc4.x
proftpd / proftpd 1.2.10-rc3 1.2.10-rc3.x
proftpd / proftpd 1.3.0-rc2 1.3.0-rc2.x
proftpd / proftpd 1.3.3 1.3.3.x
proftpd / proftpd 1.3.3-rc1 1.3.3-rc1.x
proftpd / proftpd 1.3.0-rc3 1.3.0-rc3.x