Vulnerabilities
Vulnerable Software
Netbsd:  >> Ftpd  >> 1.5  Security Vulnerabilities
ftpd before "NetBSD-ftpd 20230930" can leak information about the host filesystem before authentication via an MLSD or MLST command. tnftpd (the portable version of NetBSD ftpd) before 20231001 is also vulnerable.
CVSS Score
7.5
EPSS Score
0.002
Published
2023-10-05
ftpd in NetBSD 1.5 through 1.5.3 and 1.6 does not properly quote a digit in response to a STAT command for a filename that contains a carriage return followed by a digit, which can cause firewalls and other intermediary devices to lose proper track of the FTP session.
CVSS Score
5.0
EPSS Score
0.003
Published
2002-12-31


Contact Us

Shodan ® - All rights reserved