积极预防 及时发现
快速响应 力保恢复
用在Windows NT和9x上的Broker FTP server 5.9.5允许远程攻击者通过在...
发布时间:2001-09-20 信息来源:管理员

CNCVE编号:CNCVE-20010687 CVE编号:CAN-2001-0687 安全级别:高 漏洞中文描述: 用在Windows NT和9x上的Broker FTP server 5.9.5允许远程攻击者通过在LS命令后执行CD命令(CD C:)或把任意路径列入UNC格式中(\computernamesharename)来检索需要权限的网络服务器系统信息。 漏洞英文描述: Broker FTP server 5.9.5 for Windows NT and 9x allows a remote attacker to retrieve privileged web server system information by (1) issuing a CD command (CD C:) followed by the LS command, (2) specifying arbitrary paths in the UNC format (\computernamesh 漏洞参考: Reference: BUGTRAQ:20010610 Broker FTP Server 5.9.5.0 Buffer Overflow / DoS / Directory Traversal Reference: URL: Reference: XF:broker-ftp-cd-directory-traversal(6674) Reference: URL: