Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2010-4652

EPSS 5.49% · P90
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2010-4652

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Heap-based buffer overflow in the sql_prepare_where function (contrib/mod_sql.c) in ProFTPD before 1.3.3d, when mod_sql is enabled, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted username containing substitution tags, which are not properly handled during construction of an SQL query.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
ProFTPD mod_sql模块远程堆缓冲区溢出漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
ProFTPD 是一款高可配置性的FTP服务程序,允许对每个目录进行限制访问。 当mod_sql启用时,ProFTPD 1.3.3d之前版本中的sql_prepare_where函数(又名contrib/mod_sql.c)中存在基于堆的缓冲区溢出漏洞。远程攻击者可以借助包含替代标签的特制用户名称(在SQL查询创建过程中没有得到正确处理),导致拒绝服务(崩溃)并可能执行任意代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2010-4652

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2010-4652

登录查看更多情报信息。

Same Patch Batch · n/a · 2011-02-02 · 25 CVEs total

CVE-2010-3719Symantec IM Manager IMAdminSchedTask.asp文件eval注入漏洞
CVE-2011-0742Novell ZENworks Handheld Management ZfHIPCnd.exe缓冲区溢出漏洞
CVE-2011-0741MODx Evolution多个跨站脚本攻击漏洞
CVE-2011-0740Pleer RSS Feed Reader magpie/scripts/magpie_slashbox.php跨站脚本攻击漏洞
CVE-2011-0739Ruby Mail gem deliver功能任意Shell命令执行漏洞
CVE-2011-0738Globus MyProxy证书验证安全绕过漏洞
CVE-2011-0276HP OpenView Performance Insight Server远程任意代码执行漏洞
CVE-2011-0017Exim 'log.c'程序本地权限提升漏洞
CVE-2010-4015PostgreSQL intarray数组模块gettoken()函数缓冲区溢出漏洞
CVE-2010-3930MODx Evolution目录遍历漏洞
CVE-2010-3929MODx Evolution AjaxSearch SQL注入漏洞
CVE-2010-3854Apache CouchDB Web管理界面多个跨站脚本攻击漏洞
CVE-2010-3041Cisco WebEx WRF和ARF文件格式处理多个缓冲区溢出漏洞
CVE-2011-0755PHP mt_rand函数整数溢出漏洞
CVE-2011-0754PHP Standard PHP Library扩展SplFileInfo::getType函数后置链接漏洞
CVE-2011-0753PHP PCNTL扩展拒绝服务漏洞
CVE-2011-0752PHP extract功能输入验证漏洞
CVE-2011-0757IBM DB2 DBADM权限撤销非DDL声明执行漏洞
CVE-2011-0521Linux Kernel 'dvb_ca_ioctl()'内存破坏漏洞
CVE-2010-3270Cisco WebEx ATP文件栈缓冲区溢出漏洞

Showing top 20 of 25 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2010-4652

No comments yet


Leave a comment