ProFTPD Auth API Multiple Auth Module Authentication Bypass

This script is Copyright (C) 2007-2011 Tenable Network Security, Inc.


Synopsis :

It is possible to bypass the authentication scheme of the remote FTP
server.

Description :

The remote host is running ProFTPd. Due to a bug in the way the
remote server is configured and the way it processes the USER and PASS
commands, it is possible to log into the remote system by supplying
invalid credentials.

See also :

http://bugs.proftpd.org/show_bug.cgi?id=2922

Solution :

Upgrade to the latest (CVS) version of this software.

Risk factor :

Medium / CVSS Base Score : 5.1
(CVSS2#AV:N/AC:H/Au:N/C:P/I:P/A:P)
CVSS Temporal Score : 3.8
(CVSS2#E:U/RL:OF/RC:C)
Public Exploit Available : false

Family: FTP

Nessus Plugin ID: 25040 ()

Bugtraq ID: 23546

CVE ID: CVE-2007-2165