漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Xlight FTP Server < 3.9.5 Information Disclosure via USER Command
Vulnerability Description
Xlight FTP Server before 3.9.5 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the server's current GetTickCount() value by sending a USER command with a username ending in the :adm suffix. Attackers can trigger the admin protocol path within the standard FTP listener pre-authentication to leak timing information from the FTP 331 response without requiring a separate port or configuration change.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
通过差异性导致的信息暴露
Vulnerability Title
xlight ftp server 侧信道信息泄露漏洞
Vulnerability Description
xlight ftp server是xlight ftp server个人开发者的一款轻量级FTP服务器软件。 Xlight FTP Server 3.9.5之前版本存在侧信道信息泄露漏洞,该漏洞源于发送USER命令以:adm结尾触发admin协议路径,导致未经身份验证的攻击者泄露GetTickCount()值。
CVSS Information
N/A
Vulnerability Type
N/A