CVE Database
/

CVE-2005-1646

Back to search

CVE-2005-1646

Published: May 18, 2005

Modified: Aug 7, 2024

PUBLISHED

Description

The default installation of Fastream NETFile FTP/Web Server 7.4.6, which supports FXP, does not require that the IP address in a PORT command be the same as the IP of the logged in user, which allows remote attackers to conduct FTP Bounce attacks to bypass firewall rules or cause a denial of service.

VendorProductVersions

n/a

n/a

affected
n/a

References

ADV-2005-0556
vdb-entry
x_refsource_VUPEN
15394
third-party-advisory
x_refsource_SECUNIA
16621
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now