ProFTPD是ProFTPD团队开源的一套可配置性强的开放源代码的FTP服务器软件。 ProFTPD 1.3.9b及之前版本和1.3.10rc2及之前版本存在后置链接漏洞,该漏洞源于RNFR命令处理程序中的路径前缀问题,允许经过身份验证的FTP用户通过前缀路径(/proc/self/root)绕过目录ACL限制,利用dir_canonical_path()中的未解析符号链接组件导致dir_check()执行不匹配配置的目录块的词法路径比较,从而对DenyAll保护的目录中的文件执行重命名操作并检索这些文
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ProFTPD Project | ProFTPD | ≤ 1.3.9b |
affected |
≤ 1.3.10rc2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ProFTPD Project | ProFTPD | 0 ~ 1.3.9b | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet