Loading
A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed between November 28 and December 2, 2010. The backdoor implements a hidden FTP command trigger that, when invoked, causes the server to execute arbitrary shell commands with root privileges. This allows remote, unauthenticated attackers to run any OS command on the FTP server host.
Use CWE-912, Proftpd vendor hub and Proftpd product page to widen CVE-2010-20103 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2019-12815, CVE-2020-9273 and CVE-2023-51713 for nearby disclosures in the same product family.