CNCVE编号:CNCVE-20010027 CVE编号:CAN-2001-0027 安全级别:高 漏洞中文描述: 当用户使用“user”命令来改变帐户时,ProFTPD 中mod_sqlpw模块不能重置一个隐藏的口令,这允许经认证的攻击者获得其他用户的权限。 漏洞英文描述: mod_sqlpw module in ProFTPD does not reset a cached password when a user uses the "user" command to change accounts, which allows authenticated attackers to gain privileges of other users. 漏洞参考: XF:proftpd-modsqlpw-unauth-access BUGTRAQ:20001211 mod_sqlpw Password Caching Bug 系统类型:其他 漏洞类型:权限有效性检查错误