PT-2005-5236 · Ftgate · Ftgate

Publicado

2005-12-29

·

Atualizado

2011-03-08

·

CVE-2005-4568

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions FTGate versions 4.4.000
Description The issue allows remote attackers to execute arbitrary code via format string specifiers in the USER, PASS, and TOP commands to the POP3 server, and the LIST and AUTHENTICATE commands to the IMAP server.
Recommendations For FTGate version 4.4.000, consider disabling the vulnerable commands (USER, PASS, TOP, LIST, AUTHENTICATE) to the POP3 and IMAP servers until a patch is available. Restrict access to these commands to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-4568

Produtos afetados

Ftgate