Nessus Plugin #10452

Plugin Index

Note: This file has been created from a downloaded version of the Nessus Plugins from http://www.nessus.org/. Therefore, the information here can be outdated.

wu-ftpd SITE EXEC vulnerability

Family:
FTP
Category:
attack
Copyright:
This script is Copyright (C) 2000 A. de Bernis
Summary:
Checks if the remote FTP server sanitizes the SITE EXEC command
Version:
$Revision: 1.23 $
Cve_id:
CVE-2000-0573, CVE-1999-0997
Bugtraq_id:
1387, 2240, 726
Xrefs:
-
Description:

The remote FTP server does not properly sanitize the argument of
the SITE EXEC command.
It may be possible for a remote attacker
to gain root access.

Solution : Upgrade your wu-ftpd server (<= 2.6.0 are vulnerable)
or disable any access from untrusted users (especially anonymous).

Risk factor : High
Generiert am 27.04.2005 um 18:49:54 Uhr.