Vulnerability CVE-1999-1345


Published: 1999-10-05   Modified: 2012-02-12

Description:
Auto_FTP.pl script in Auto_FTP 0.2 uses the /tmp/ftp_tmp as a shared directory with insecure permissions, which allows local users to (1) send arbitrary files to the remote server by placing them in the directory, and (2) view files that are being transferred.

CVSS2 => (AV:L/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.6/10
6.4/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Auto ftp -> Auto ftp 

 References:
http://marc.info/?l=bugtraq&m=93923873006014&w=2

Copyright 2024, cxsecurity.com

 

Back to Top