Back to search
CVE-2009-5012
Published: Oct 19, 2010
Modified: Sep 17, 2024
PUBLISHED
Description
ftpserver.py in pyftpdlib before 0.5.2 does not require the l permission for the MLST command, which allows remote authenticated users to bypass intended access restrictions and list the root directory via an FTP session.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://code.google.com/p/pyftpdlib/source/browse/trunk/HISTORY
x_refsource_CONFIRM
http://code.google.com/p/pyftpdlib/source/detail?r=596
x_refsource_CONFIRM
http://code.google.com/p/pyftpdlib/issues/detail?id=114
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now