CVE-2006-5815
60Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 74%
from disclosure to weapon19 days
Published on NVDNov 8
1st PoC+19d
metasploit+18d
exploitation probability
74%top 1% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Stack-based buffer overflow in the sreplace function in ProFTPD 1.3.0 and earlier allows remote attackers, probably authenticated, to cause a denial of service and execute arbitrary code, as demonstrated by vd_proftpd.pm, a "ProFTPD remote exploit."
Affected products
n/a · n/apublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/16852unverifiedexploitdbwww.exploit-db.com/exploits/2856unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://bugs.proftpd.org/show_bug.cgi?id=2858http://gleg.net/vulndisco_meta.shtmlhttps://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=214820http://secunia.com/advisories/22803http://secunia.com/advisories/22821http://secunia.com/advisories/23000http://secunia.com/advisories/23069http://secunia.com/advisories/23125http://secunia.com/advisories/23174http://secunia.com/advisories/23179http://secunia.com/advisories/23184http://secunia.com/advisories/23207