Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Directory traversal vulnerability in BisonFTP Server 4 release 2 allows remote attackers to (1) list directories above the root via an 'ls @../' command, or (2) list files above the root via a "mget @../FILE" command.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
BisonFTP远程信息泄露漏洞
Vulnerability Description
BisonFTP是一款可使用在Microsoft Windows 9x/NT操作系统上的FTP服务程序。 BisonFTP对用户提交的特殊字符缺少正确过滤,远程攻击者可以利用这个漏洞以FTP进程权限在系统上查看目录列表。 BisonFTP对'@../'字符请求缺少正确处理,发送包含'@../'字符的'ls'命令,可使FTP服务器返回FTP ROOT父目录的列表信息。
CVSS Information
N/A
Vulnerability Type
N/A