Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Buffer overflows in NetWin Authentication Module (NWAuth) 3.0b and earlier, as implemented in DMail, SurgeFTP, and possibly other packages, could allow attackers to execute arbitrary code via long arguments to (1) the -del command or (2) the -lookup command.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Netwin NWAuth 缓冲区溢出漏洞
Vulnerability Description
CVE(CAN) ID: CAN-2001-1355 NWAuth是Netwin的外部认证模块,被好几个Netwin的产品所采用。 发现NWAuth的"-del"和"-lookup"命令存在缓冲区溢出漏洞,其中前者只可能被管 理员所利用,而后者可以为任意用户利用。 利用这个漏洞,攻击者可能通过使用NWAuth的服务执行任意代码,这可能会导致完全的 系统控制。
CVSS Information
N/A
Vulnerability Type
N/A