CNCVE编号:CNCVE-20010450 CVE编号:CAN-2001-0450 安全级别:中 漏洞中文描述: Transsoft FTP Broker 5.5以前的版本中的目录遍历漏洞导致攻击者通过在文件名中的“..”来(1)用DELETE删除任意文件(2) 用LIST列出任意目录。 漏洞英文描述: Directory traversal vulnerability in Transsoft FTP Broker before 5.5 allows attackers to (1) delete arbitrary files via DELETE, or (2) list arbitrary directories via LIST, via a .. (dot dot) in the file name. 漏洞参考: Reference: BUGTRAQ:20010303 Broker Ftp Server 5.0 Vulnerability Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0533.html Reference: CONFIRM:http://www.ftp-broker.com/cgibin/Pageexe.exe?H=4143&P=0&C=0 Reference: XF:broker-ftp- 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:输入有效性检查错误