S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2010-20103

9.3
CVSScritical
Exploitable remotely over the internet · no authentication required.
Description

A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed between November 28 and December 2, 2010. The backdoor implements a hidden FTP command trigger that, when invoked, causes the server to execute arbitrary shell commands with root privileges. This allows remote, unauthenticated attackers to run any OS command on the FTP server host.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
proftpd (professional ftp daemon)
Updated Sep 18, 2026View on NVD →
S4E scanners

CVE history: proftpd (professional ftp daemon)

Predict next CVE date with AI

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →