PT-1999-1666 · Auto Ftp · Auto Ftp
Publicado
1999-10-05
·
Atualizado
2016-10-18
·
CVE-1999-1345
CVSS v2.0
4.6
Média
| Vetor | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Auto FTP version 0.2
Description:
The issue concerns the Auto FTP.pl script in Auto FTP, which utilizes the /tmp/ftp tmp directory with insecure permissions. This setup allows local users to send arbitrary files to the remote server by placing them in the directory and to view files that are being transferred.
Recommendations:
For Auto FTP version 0.2, consider changing the permissions of the /tmp/ftp tmp directory to secure it, or use a different directory with proper access controls to prevent unauthorized access and file manipulation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Auto Ftp