The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsThere is no fixed version for proftpd/proftpd.
Affected versions of this package are vulnerable to Symlink Attack via the RNFR command handler when paths are prefixed with /proc/self/root. An attacker can bypass directory access restrictions by exploiting unresolved symlink components in the dir_canonical_path process, causing dir_check to perform lexical path comparisons that do not match any configured Directory block, thereby enabling unauthorized rename operations and subsequent retrieval of files in protected directories. This is only exploitable if the session is not configured with DefaultRoot (chroot), as chroot changes the directory to which /proc/self/root resolves.