PT-1999-1666 · Auto Ftp · Auto Ftp

Publicado

1999-10-05

·

Atualizado

2016-10-18

·

CVE-1999-1345

CVSS v2.0

4.6

Média

VetorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Auto FTP version 0.2
Description: The issue concerns the Auto FTP.pl script in Auto FTP, which utilizes the /tmp/ftp tmp directory with insecure permissions. This setup allows local users to send arbitrary files to the remote server by placing them in the directory and to view files that are being transferred.
Recommendations: For Auto FTP version 0.2, consider changing the permissions of the /tmp/ftp tmp directory to secure it, or use a different directory with proper access controls to prevent unauthorized access and file manipulation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-1999-1345

Produtos afetados

Auto Ftp