CVE-2011-4130
Use-after-free vulnerability in the Response API in ProFTPD before 1.3.3g allows remote authenticated users to execute arbitrary code via vectors involving an error that occurs after an FTP data transfer.
- Affected products
- Proftpd
- Proftpd
- ≤ 1.3.3, 1.2.0, 1.2.1, 1.2.2, 1.2.3, 1.2.4, 1.2.5, 1.2.6, 1.2.7, 1.2.8, 1.2.9, 1.2.10, 1.3.0, 1.3.1, 1.3.2
- Fix
- Available
- CVSS 2.0
- 9.0 HIGH
- EPSS
- 12.6% (96th percentile)
- Weakness
- CWE-399
- NVD status
- Modified
- Published
- 2011-12-06
CVE-2011-4130 at NVD
3 known exploits for CVE-2011-4130
Proof-of-concept code and exploit modules indexed by Sploitus