CVE-2010-20103 - CVE House
Back to Database
Status published Critical CVE-2010-20103

ProFTPD 1.3.3c Backdoor Command Execution

Vulnerability Description

A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed between November 28 and December 2, 2010. The backdoor implements a hidden FTP command trigger that, when invoked, causes the server to execute arbitrary shell commands with root privileges. This allows remote, unauthenticated attackers to run any OS command on the FTP server host.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2010-20103

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

ProFTPD Project

View all reports →

Affected Software

ProFTPD (Professional FTP Daemon)
Vulnerable Versions:
1.3.3c

Timeline

Official Publish: August 20th, 2025
Last Modified: July 15th, 2026
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.