vendor:
ProFTPD
by:
TJ Saunders
7.5
CVSS
HIGH
Unauthenticated mod_copy SITE CPFR/SITE CPTO Commands
264
CWE
Product Name: ProFTPD
Affected Version From: 1.3.5rc3
Affected Version To: 1.3.5rc3
Patch Exists: YES
Related CWE: N/A
CPE: a:proftpd:proftpd:1.3.5rc3
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2015
Unauthenticated mod_copy SITE CPFR/SITE CPTO Commands Vulnerability
Vadim Melihow reported a critical issue with proftpd installations that use the mod_copy module's SITE CPFR/SITE CPTO commands; mod_copy allows these commands to be used by unauthenticated clients. He provides another, scarier example, where a malicious user can copy a file from the server to a php script, which can be run by the php interpreter.
Mitigation:
Disable mod_copy module or restrict access to authenticated users.