Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Format string vulnerability in the log function for jftpgw 0.13.4 and earlier allows remote authenticated users to execute arbitrary code via format string specifiers in certain syslog messages.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
JFTPGW远程Syslog格式串处理漏洞
Vulnerability Description
jftpgw是一款FTP代理程序。 jftpgw FTP proxy存在远程格式串问题,远程攻击者可以利用这个漏洞以jftpgw进程权限在系统上执行任意指令。 问题是log()函数中的syslog(3)存在格式串问题,提交恶意格式串数据可破坏内存数据,可能以jftpgw进程权限在系统上执行任意指令。
CVSS Information
N/A
Vulnerability Type
N/A