Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-28x5-qp9q-fqqf

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Microsoft FTP Service 7.0 and 7.5 for Internet Information Services (IIS) processes unspecified commands before TLS is enabled for a session, which allows remote attackers to obtain sensitive information by reading the replies to these commands, aka "FTP Command Injection Vulnerability."

Microsoft FTP Service 7.0 and 7.5 for Internet Information Services (IIS) processes unspecified commands before TLS is enabled for a session, which allows remote attackers to obtain sensitive information by reading the replies to these commands, aka "FTP Command Injection Vulnerability."

EPSS

Процентиль: 95%
0.19645
Средний

Дефекты

CWE-200

Связанные уязвимости

nvd
около 13 лет назад

Microsoft FTP Service 7.0 and 7.5 for Internet Information Services (IIS) processes unspecified commands before TLS is enabled for a session, which allows remote attackers to obtain sensitive information by reading the replies to these commands, aka "FTP Command Injection Vulnerability."

CVSS3: 5.3
fstec
около 13 лет назад

Уязвимость пакета сетевых служб Internet Information Services FTP операционных систем Windows, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 95%
0.19645
Средний

Дефекты

CWE-200