Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
mirror --script in lftp before 3.5.9 does not properly quote shell metacharacters, which might allow remote user-assisted attackers to execute shell commands via a malicious script. NOTE: it is not clear whether this issue crosses security boundaries, since the script already supports commands such as "get" which could overwrite executable files.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
lftp 安全漏洞
Vulnerability Description
lftp是LFTP开源的一个基于命令行的文件传输软件。 lftp 3.5.9之前版本存在安全漏洞,该漏洞源于没有正确引用shell元字符。
CVSS Information
N/A
Vulnerability Type
N/A