Show filters
14 Total Results
Displaying 11-14 of 14
Sort by:
Attacker Value
Unknown
CVE-2009-5012
Disclosure Date: October 19, 2010 (last updated October 04, 2023)
ftpserver.py in pyftpdlib before 0.5.2 does not require the l permission for the MLST command, which allows remote authenticated users to bypass intended access restrictions and list the root directory via an FTP session.
0
Attacker Value
Unknown
CVE-2009-5011
Disclosure Date: October 19, 2010 (last updated October 04, 2023)
Race condition in the FTPHandler class in ftpserver.py in pyftpdlib before 0.5.2 allows remote attackers to cause a denial of service (daemon outage) by establishing and then immediately closing a TCP connection, leading to the getpeername function having an ENOTCONN error, a different vulnerability than CVE-2010-3494.
0
Attacker Value
Unknown
CVE-2007-6738
Disclosure Date: October 19, 2010 (last updated October 04, 2023)
pyftpdlib before 0.1.1 does not choose a random value for the port associated with the PASV command, which makes it easier for remote attackers to obtain potentially sensitive information about the number of in-progress data connections by reading the response to this command.
0
Attacker Value
Unknown
CVE-2007-6737
Disclosure Date: October 19, 2010 (last updated October 04, 2023)
FTPServer.py in pyftpdlib before 0.2.0 does not increment the attempted_logins count for a USER command that specifies an invalid username, which makes it easier for remote attackers to obtain access via a brute-force attack.
0