![]() |
Startseite ▼ Bookkeeping
Online ▼ Sicherheits
Überprüfungs ▼
Verwaltetes
DNS ▼
Info
Bestellen/Erneuern
FAQ
AUP
Dynamic DNS Clients
Domaine konfigurieren Dyanmic DNS Update Password Netzwerk
Überwachung ▼
Enterprise
Erweiterte
Standard
Gratis Test
FAQ
Preis/Funktionszusammenfassung
Bestellen
Beispiele
Konfigurieren/Status Alarm Profile | ||
Test Kennung: | 1.3.6.1.4.1.25623.1.0.100679 |
Kategorie: | FTP |
Titel: | pyftpd Multiple Vulnerabilities |
Zusammenfassung: | pyftpd is prone to multiple vulnerabilities. |
Beschreibung: | Summary: pyftpd is prone to multiple vulnerabilities. Vulnerability Insight: 1. pyftpd is prone to multiple default-account vulnerabilities. These issues stem from a design flaw that makes several accounts available to remote attackers. Successful exploits allow remote attackers to gain unauthorized access to a vulnerable application. 2. pyftpd creates temporary files in an insecure manner. An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application. Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files, which may result in a denial of service. Other attacks may also be possible. Affected Software/OS: pyftpd prior to 0.8.5 are affected. Solution: Vendor updates are available. Please see the references for more information. CVSS Score: 5.0 CVSS Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N |
Querverweis: |
Common Vulnerability Exposure (CVE) ID: CVE-2010-2072 BugTraq ID: 40842 http://www.securityfocus.com/bid/40842 http://www.openwall.com/lists/oss-security/2010/06/13/1 XForce ISS Database: pyftpd-logfile-symlink(59429) https://exchange.xforce.ibmcloud.com/vulnerabilities/59429 Common Vulnerability Exposure (CVE) ID: CVE-2010-2073 BugTraq ID: 40839 http://www.securityfocus.com/bid/40839 http://www.openwall.com/lists/oss-security/2010/06/13/2 XForce ISS Database: pyftpd-default-account(59431) https://exchange.xforce.ibmcloud.com/vulnerabilities/59431 |
Copyright | Copyright (C) 2010 Greenbone AG |
Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus. Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten. |