Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-48651

EPSS 36.59% · P97
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2024-48651

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplemental groups from mod_sql.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
ProFTPD 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
ProFTPD是ProFTPD开源的一套可配置性强的开放源代码的FTP服务器软件。 ProFTPD 1.3.8b版本存在安全漏洞,该漏洞源于缺少来自mod_sql的补充组,补充组继承授予了对GID 0的意外访问权限。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2024-48651

#POC DescriptionSource LinkShenlong Link
1ProFTPD versions through 1.3.8b (before commit cec01cc) contain a vulnerability in the mod_sql module due to improper handling of supplemental groups. This flaw allows authenticated users without explicitly assigned supplemental groups to inherit root group privileges (GID 0), potentially granting unauthorized access to sensitive system resources. https://github.com/projectdiscovery/nuclei-templates/blob/main/network/cves/2024/CVE-2024-48651.yamlPOC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-48651

登录查看更多情报信息。

Same Patch Batch · n/a · 2024-11-29 · 40 CVEs total

CVE-2024-541594.1 MEDIUMStalld 安全漏洞
CVE-2024-53623TP-LINK Archer C7 安全漏洞
CVE-2024-36616FFmpeg 安全漏洞
CVE-2024-36623Moby 安全漏洞
CVE-2024-36619FFmpeg 安全漏洞
CVE-2024-36615FFmpeg 安全漏洞
CVE-2024-36611Symfony 安全漏洞
CVE-2024-36617FFmpeg 安全漏洞
CVE-2024-53505SiYuan 安全漏洞
CVE-2024-53507SiYuan 安全漏洞
CVE-2024-36620Moby 安全漏洞
CVE-2024-53504Siyuan 安全漏洞
CVE-2024-53506SiYuan 安全漏洞
CVE-2024-52781Digital China Networks多款产品 安全漏洞
CVE-2024-52777Digital China Networks多款产品 安全漏洞
CVE-2024-52778Digital China Networks多款产品 安全漏洞
CVE-2024-52780Digital China Networks多款产品 安全漏洞
CVE-2024-52779Digital China Networks多款产品 安全漏洞
CVE-2024-52782Digital China Networks多款产品 安全漏洞
CVE-2024-47193WithSecure多款产品 安全漏洞

Showing top 20 of 40 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2024-48651

No comments yet


Leave a comment