7.5

CVE-2001-1500

ProFTPD 1.2.2rc2, and possibly other versions, does not properly verify reverse-resolved hostnames by performing forward resolution, which allows remote attackers to bypass ACLs or cause an incorrect client hostname to be logged.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Proftpd Project ≫ Proftpd Version 1.2
Proftpd Project ≫ Proftpd Version 1.2.0_rc3
Proftpd Project ≫ Proftpd Version 1.2.1
Proftpd Project ≫ Proftpd Version 1.2.2
Proftpd Project ≫ Proftpd Version 1.2.2_rc1
Proftpd Project ≫ Proftpd Version 1.2.2_rc2
Proftpd Project ≫ Proftpd Version 1.2_pre1
Proftpd Project ≫ Proftpd Version 1.2_pre2
Proftpd Project ≫ Proftpd Version 1.2_pre3
Proftpd Project ≫ Proftpd Version 1.2_pre4
Proftpd Project ≫ Proftpd Version 1.2_pre5
Proftpd Project ≫ Proftpd Version 1.2_pre6
Proftpd Project ≫ Proftpd Version 1.2_pre7
Proftpd Project ≫ Proftpd Version 1.2_pre8
Proftpd Project ≫ Proftpd Version 1.2_pre9
Proftpd Project ≫ Proftpd Version 1.2_pre10
Proftpd Project ≫ Proftpd Version 1.2_pre11
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 12.45% 0.957
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000450
http://www.mandriva.com/security/advisories?name=MDKSA-2002:005
http://www.securityfocus.com/archive/1/212805
http://www.securityfocus.com/bid/3310
Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/7126