![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.10086 |
Category: | FTP |
Title: | Ftp PASV on connect crashes the FTP server |
Summary: | NOSUMMARY |
Description: | Description: The remote FTP server dies and dump core when it is issued a PASV command as soon as the client connects. The FTP server is very likely to write a world readable core file which contains portions of the passwd file. This allows local users to obtain the shadowed passwd file. Risk factor : High. Solution : Upgrade your FTP server to a newer version or disable it |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-1999-0075 Bugtraq: 19961016 Re: ftpd bug? Was: bin/1805: Bug in ftpd (Google Search) http://www.osvdb.org/5742 XForce ISS Database: ftp-pasvcore |
Copyright | This script is Copyright (C) 1999 Renaud Deraison |
This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |