Directory Traversal Vulnerabilities in ProFTPD by The ProFTPD Project
CVE-2010-3867
Currently unrated
What is CVE-2010-3867?
The ProFTPD software, specifically in the mod_site_misc module, has several directory traversal vulnerabilities. These flaws allow remote authenticated users to execute potentially damaging actions such as creating or deleting directories, establishing symbolic links, and altering file timestamps. This is achieved through crafted directory traversal sequences in commands like SITE MKDIR, SITE RMDIR, SITE SYMLINK, or SITE UTIME, leading to possible system compromises.
