积极预防 及时发现
快速响应 力保恢复
wu-ftpd 2.6.0以及早期版本中的lreply函数没有完全净化一个不可信的格式化字符串,这导...
发布时间:2002-05-20 信息来源:管理员

CNCVE编号:CNCVE-20000573 CVE编号:CVE-2000-0573 安全级别:中 漏洞中文描述: wu-ftpd 2.6.0以及早期版本中的lreply函数没有完全净化一个不可信的格式化字符串,这导致远程攻击者可以通过SITE EXEC命令执行任意命令。 漏洞英文描述: The lreply function in wu-ftpd 2.6.0 and earlier does not properly cleanse an untrusted format string, which allows remote attackers to execute arbitrary commands via the SITE EXEC command. 漏洞参考: 系统类型:其他 漏洞类型:其他