积极预防 及时发现
快速响应 力保恢复
FaSTream FTP++ Server 2.0 允许远程攻击者执行包含驱动器名(如C:)和路径名...
发布时间:2001-06-02 信息来源:管理员

CNCVE编号:CNCVE-20010255 CVE编号:CAN-2001-0255 安全级别:中 漏洞中文描述: FaSTream FTP++ Server 2.0 允许远程攻击者执行包含驱动器名(如C:)和路径名的ls命令请求. 漏洞英文描述: FaSTream FTP++ Server 2.0 allows remote attackers to list arbitrary directories by using the "ls" command and including the drive letter name (e.g. C:) in the requested pathname. 漏洞参考: BUGTRAQ:20010119 Multiple Vulnerabilities In FaSTream FTP++ (+ ICS Tftpserver DoS) | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98021181215325&w=2 | BID:2267 | URL:http://www.securityfocus.com/bid/2267 | XF:fastream-ftp-path-disclosure 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:设计错误