20050725 Chroot Security Group Advisory 2005-07-25 -- ftplocatemailing list
http://marc.info/?l=bugtraq&m=112230697123357&w=2 CVE-2005-2420
FtpLocate 2.02 - 'current' Remote Command Execution
Record summary
CVE-2005-2420 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit.
Description
flsearch.pl in FtpLocate 2.02 allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP GET request.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBFtpLocate 2.02 - 'current' Remote Command ExecutionExploitDB exploitby newbugNot analyzed1 file
References
716218Third-party advisory
http://secunia.com/advisories/16218 1014570vdb entry
http://securitytracker.com/id?1014570 18305vdb entry
http://www.osvdb.org/18305 14367vdb entry
http://www.securityfocus.com/bid/14367 ftplocate-fsite-command-execution(21540)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/21540 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2005-2420