PT-2000-1799 · Texas Imperial · Wftpd Pro+1

Publicado

2000-11-14

·

Atualizado

2017-10-10

·

CVE-2000-0876

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions WFTPD and WFTPD Pro version 2.41 RC12
Description The issue allows remote attackers to obtain the full pathname of the server. This is achieved by sending a "%C" command, which generates an error message that includes the pathname.
Recommendations For WFTPD and WFTPD Pro version 2.41 RC12, consider restricting access to the "%C" command to prevent the disclosure of the server's pathname until a fix is available.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2000-0876

Produtos afetados

Wftpd
Wftpd Pro