The FTP service in Magic Winmail Server 4.0 Build 1112 does not verify that the IP address in a PORT command is the same as the IP address of the user of the FTP session, which allows remote authenticated users to use the server as an intermediary for port scanning.
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:54
Type | Values Removed | Values Added |
---|---|---|
References | () http://marc.info/?l=bugtraq&m=110685011825461&w=2 - | |
References | () http://secunia.com/advisories/14053 - | |
References | () http://securitytracker.com/id?1013017 - | |
References | () http://www.securityfocus.com/bid/12388 - Patch, Vendor Advisory | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/19115 - |
Information
Published : 2005-01-27 05:00
Updated : 2024-11-20 23:54
NVD link : CVE-2005-0315
Mitre link : CVE-2005-0315
CVE.ORG link : CVE-2005-0315
JSON object : View
Products Affected
amax_information_technologies
- magic_winmail_server
CWE