Gene6 FTP Server does not properly restrict access to the control console, which allows local users to modify the server configuration and gain privileges, as demonstrated by defining a SITE command.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=111026585431080&w=2 | mailing list |
http://secway.org/Advisory/ad20050303.txt | vendor advisory |
http://www.securityfocus.com/bid/12739 | vdb entry patch vendor advisory |
http://marc.info/?l=bugtraq&m=111022496826680&w=2 | mailing list |
http://secunia.com/advisories/14436 | third party advisory vendor advisory |