Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x25r-grxc-v6g7

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The default installation of Fastream NETFile FTP/Web Server 7.4.6, which supports FXP, does not require that the IP address in a PORT command be the same as the IP of the logged in user, which allows remote attackers to conduct FTP Bounce attacks to bypass firewall rules or cause a denial of service.

The default installation of Fastream NETFile FTP/Web Server 7.4.6, which supports FXP, does not require that the IP address in a PORT command be the same as the IP of the logged in user, which allows remote attackers to conduct FTP Bounce attacks to bypass firewall rules or cause a denial of service.

EPSS

Процентиль: 62%
0.00428
Низкий

Связанные уязвимости

nvd
больше 20 лет назад

The default installation of Fastream NETFile FTP/Web Server 7.4.6, which supports FXP, does not require that the IP address in a PORT command be the same as the IP of the logged in user, which allows remote attackers to conduct FTP Bounce attacks to bypass firewall rules or cause a denial of service.

EPSS

Процентиль: 62%
0.00428
Низкий