Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2009-5012

Опубликовано: 19 окт. 2010
Источник: debian

Описание

ftpserver.py in pyftpdlib before 0.5.2 does not require the l permission for the MLST command, which allows remote authenticated users to bypass intended access restrictions and list the root directory via an FTP session.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-pyftpdlibfixed0.5.2-1package

Связанные уязвимости

nvd
почти 16 лет назад

ftpserver.py in pyftpdlib before 0.5.2 does not require the l permission for the MLST command, which allows remote authenticated users to bypass intended access restrictions and list the root directory via an FTP session.

github
больше 4 лет назад

Improper Access Control in pyftpdlib