7.5

CVE-2001-1500

ProFTPD 1.2.2rc2, and possibly other versions, does not properly verify reverse-resolved hostnames by performing forward resolution, which allows remote attackers to bypass ACLs or cause an incorrect client hostname to be logged.

Data is provided by the National Vulnerability Database (NVD)
Proftpd ProjectProftpd Version1.2
Proftpd ProjectProftpd Version1.2.0_rc3
Proftpd ProjectProftpd Version1.2.1
Proftpd ProjectProftpd Version1.2.2
Proftpd ProjectProftpd Version1.2.2_rc1
Proftpd ProjectProftpd Version1.2.2_rc2
Proftpd ProjectProftpd Version1.2_pre1
Proftpd ProjectProftpd Version1.2_pre2
Proftpd ProjectProftpd Version1.2_pre3
Proftpd ProjectProftpd Version1.2_pre4
Proftpd ProjectProftpd Version1.2_pre5
Proftpd ProjectProftpd Version1.2_pre6
Proftpd ProjectProftpd Version1.2_pre7
Proftpd ProjectProftpd Version1.2_pre8
Proftpd ProjectProftpd Version1.2_pre9
Proftpd ProjectProftpd Version1.2_pre10
Proftpd ProjectProftpd Version1.2_pre11
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.09% 0.759
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P