CNCVE编号:CNCVE-20010550 CVE编号:CAN-2001-0550 安全级别:高 漏洞中文描述: wu-ftpd 2.6.1 允许远程攻击者通过传向诸如CWD的“~{”参数来执行任意命令,这不能被glob函数正确处理。 漏洞英文描述: wu-ftpd 2.6.1 allows remote attackers to execute arbitrary commands via a "~{" argument to commands such as CWD, which is not properly handled by the glob function. 漏洞参考: Reference: VULN-DEV:20010430 some ftpd implementations mishandle CWD ~{ Reference: URL:http://www.securityfocus.com/archive/82/180823 Reference: BUGTRAQ:20011128 CORE-20011001: Wu-FTP glob heap corruption vulnerability Reference: URL:http://marc.theaim 系统类型:其他 漏洞类型:异常处理错误