Open-FTPD Multiple Command Authentication Bypass Vulnerabilities
BID:41479
Info
Open-FTPD Multiple Command Authentication Bypass Vulnerabilities
| Bugtraq ID: | 41479 |
| Class: | Design Error |
| CVE: |
CVE-2010-2620 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 18 2010 12:00AM |
| Updated: | Aug 13 2013 05:46AM |
| Credit: | Serge Gorbunov |
| Vulnerable: |
Open-FTPD Open-FTPD 1.2 |
| Not Vulnerable: | |
Discussion
Open-FTPD Multiple Command Authentication Bypass Vulnerabilities
Open-FTPD is prone to multiple authentication-bypass vulnerabilities.
Attackers can exploit these issues to gain unauthorized access to certain portions of the affected application and perform unauthorized actions.
Open-FTPD (Open&Compact Ftp Server) 1.2 is vulnerable; other versions may be affected.
http://drupal.org/node/207891
Open-FTPD is prone to multiple authentication-bypass vulnerabilities.
Attackers can exploit these issues to gain unauthorized access to certain portions of the affected application and perform unauthorized actions.
Open-FTPD (Open&Compact Ftp Server) 1.2 is vulnerable; other versions may be affected.
http://drupal.org/node/207891
Exploit / POC
Open-FTPD Multiple Command Authentication Bypass Vulnerabilities
The following exploits are available:
The following exploits are available:
Solution / Fix
Open-FTPD Multiple Command Authentication Bypass Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Open-FTPD Multiple Command Authentication Bypass Vulnerabilities
References:
References:
- Open-FTPD Homepage (Open-FTPD)