Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cerberus FTP Server Enterprise Edition prior to versions 11.0.3 and 10.0.18 allows an authenticated attacker to create files, display hidden files, list directories, and list files without the permission to zip and download (or unzip and upload) files. There are multiple ways to bypass certain permissions by utilizing the zip and unzip features. As a result, users without permission can see files, folders, and hidden files, and can create directories without permission.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Cerberus FTP Server 安全漏洞
Vulnerability Description
Cerberus FTP Server(企业版)11.0.3之前版本和10.0.18之前版本中存在安全漏洞,该漏洞源于解压和压缩功能没有进行正确的权限验证。攻击者可借助特制的请求利用该漏洞创建文件,展示被隐藏的文件,列出目录和文件。
CVSS Information
N/A
Vulnerability Type
N/A