Skip to content
COOEY

EXPOSURES › CVE-2010-20103

CVE-2010-20103

CRITICAL
DETAIL
SourceNVD · cve Published2025-08-20 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2010-20103 ↗

▸ RECOMMENDED ACTION  Critical severity — schedule patching of the affected products.

DESCRIPTION

A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed between November 28 and December 2, 2010. The backdoor implements a hidden FTP command trigger that, when invoked, causes the server to execute arbitrary shell commands with root privileges. This allows remote, unauthenticated attackers to run any OS command on the FTP server host.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.