Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The FTP service in Magic Winmail Server 4.0 Build 1112 does not verify that the IP address in a PORT command is the same as the IP address of the user of the FTP session, which allows remote authenticated users to use the server as an intermediary for port scanning.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Magicwinmail WinmailServer FTP 中间人攻击漏洞
Vulnerability Description
Magic Winmail Server是一款多功能的WebMail系统。 Magic Winmail Server 4.0 build 1112版本中的FTP服务存在中间人攻击漏洞。 由于其FTP服务中PORT命令中没有校验IP地址是否为用户FTP会话中的IP地址,远程攻击者可利用此漏洞将该服务期作为端口扫描的中间人服务器。
CVSS Information
N/A
Vulnerability Type
N/A