Incomplete blacklist vulnerability in NULL FTP Server Free and Pro...
Vulnerability Description
Incomplete blacklist vulnerability in NULL FTP Server Free and Pro 1.1.0.7 allows remote authenticated users to execute arbitrary commands via a custom SITE command containing shell metacharacters such as "&" (ampersand) in the middle of an argument.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2008-6534
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.exploit-db.com/exploits/7355
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47099
- http://www.securityfocus.com/bid/32656
- http://vuln.sg/nullftpserver1107-en.html
- http://secunia.com/advisories/32999
- http://www.vupen.com/english/advisories/2008/3367
- http://www.osvdb.org/50486
- http://www.vwsolutions.com/knowledgeBase/releaseNotes.aspx?productId=14
Affected Vendor
vwsolutions
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.