PT-2002-2272 · Ncftp+2 · Ncftp+3
Publicado
2002-12-17
·
Atualizado
2018-10-30
·
CVE-2002-1345
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
No specific software name or versions are mentioned, so the description is:
UNIX systems (affected versions not specified)
Description:
The issue concerns directory traversal vulnerabilities in multiple FTP clients on UNIX systems. These vulnerabilities allow remote malicious FTP servers to create or overwrite files as the client user via filenames containing
/absolute/path or .. (dot dot) sequences.Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Ncftp
Openbsd
Solaris
Sunos