Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
ProFTPD before 1.3.5e and 1.3.6 before 1.3.6rc5 controls whether the home directory of a user could contain a symbolic link through the AllowChrootSymlinks configuration option, but checks only the last path component when enforcing AllowChrootSymlinks. Attackers with local access could bypass the AllowChrootSymlinks control by replacing a path component (other than the last one) with a symbolic link. The threat model includes an attacker who is not granted full filesystem access by a hosting provider, but can reconfigure the home directory of an FTP user.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ProFTPD 安全漏洞
Vulnerability Description
ProFTPD是ProFTPD团队的一套开源的FTP服务器软件。该软件具有可配置性强、安全、稳定等特点。 ProFTPD 1.3.5e之前的版本和1.3.6rc5之前的1.3.6版本中存在安全漏洞。攻击者可通过使用符号链接替换路径组件利用该漏洞绕过AllowChrootSymlinks控制。
CVSS Information
N/A
Vulnerability Type
N/A