7.5

CVE-2005-1646

Exploit
The default installation of Fastream NETFile FTP/Web Server 7.4.6, which supports FXP, does not require that the IP address in a PORT command be the same as the IP of the logged in user, which allows remote attackers to conduct FTP Bounce attacks to bypass firewall rules or cause a denial of service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
FastreamNetfile Ftp Web Server Version7.4.6
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.74% 0.748
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/15394
Vendor Advisory
http://www.osvdb.org/16621
http://www.security.org.sg/vuln/netfileftp746port.html
Patch
Exploit
http://www.vupen.com/english/advisories/2005/0556