积极预防 及时发现
快速响应 力保恢复
当 “Restrict to home directory”选项被激活时,Winsock FTPd ...
发布时间:2001-01-09 信息来源:管理员

CNCVE编号:CNCVE-20001101 CVE编号:CAN-2000-1101 安全级别:中 漏洞中文描述: 当 “Restrict to home directory”选项被激活时,Winsock FTPd (WFTPD) 3.00 和 2.41中的目录遍历漏洞允许本地用户通过一个“/../”字符串(“..”攻击的变种)来访问home目录之外的目录。 漏洞英文描述: Directory traversal vulnerability in Winsock FTPd (WFTPD) 3.00 and 2.41 with the "Restrict to home directory" option enabled allows local users to escape the home directory via a "/../" string, a variation of the .. (dot dot) attack. 漏洞参考: BUGTRAQ:20001127 Vulnerability in Winsock FTPD 2.41/3.00 (Pro) | URL:http://archives.neohapsis.com/archives/bugtraq/2000-11/0386.html | BID:2005 | URL:http://www.securityfocus.com/bid/2005 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:权限有效性检查错误