PT-2001-1492 · Gene6 · Gene6 G6 Ftp Server+1

Publicado

2001-05-24

·

Atualizado

2017-12-19

·

CVE-2001-0263

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Gene6 G6 FTP Server version 2.0 (aka BPFTP Server 2.10)
Description The issue allows attackers to read file attributes outside of the web root using the (1) SIZE and (2) MDTM commands when the "show relative paths" option is not enabled.
Recommendations For Gene6 G6 FTP Server version 2.0 (aka BPFTP Server 2.10), consider enabling the "show relative paths" option to prevent attackers from reading file attributes outside of the web root via the SIZE and MDTM commands.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2001-0263

Produtos afetados

Bpftp Server
Gene6 G6 Ftp Server