pyftpd Remote Default Account Vulnerabilities
BID:40839
Info
pyftpd Remote Default Account Vulnerabilities
| Bugtraq ID: | 40839 |
| Class: | Design Error |
| CVE: |
CVE-2010-2073 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 14 2010 12:00AM |
| Updated: | Apr 13 2015 09:02PM |
| Credit: | Henri Salo |
| Vulnerable: |
pyftpd pyftpd 0.8.4 pyftpd pyftpd 0.8 pyftpd pyftpd 0.6 pyftpd pyftpd 0.5 Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 |
| Not Vulnerable: |
pyftpd pyftpd 0.8.5 |
Discussion
pyftpd Remote Default Account Vulnerabilities
pyftpd is prone to multiple default-account vulnerabilities. These issues stem from a design flaw that makes several accounts available to remote attackers.
Successful exploits allow remote attackers to gain unauthorized access to a vulnerable application.
pyftpd prior to 0.8.5 are affected.
pyftpd is prone to multiple default-account vulnerabilities. These issues stem from a design flaw that makes several accounts available to remote attackers.
Successful exploits allow remote attackers to gain unauthorized access to a vulnerable application.
pyftpd prior to 0.8.5 are affected.
Exploit / POC
pyftpd Remote Default Account Vulnerabilities
Attackers can use an FTP client to exploit this issue.
Attackers can use an FTP client to exploit this issue.
Solution / Fix
pyftpd Remote Default Account Vulnerabilities
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
pyftpd Remote Default Account Vulnerabilities
References:
References: