First published: Thu Nov 30 1995(Updated: )
Certain configurations of wu-ftp FTP server 2.4 use a _PATH_EXECPATH setting to a directory with dangerous commands, such as /bin, which allows remote authenticated users to gain root access via the "site exec" command.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
wu-ftpd | =2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-0080 is considered a critical vulnerability due to its potential to allow remote authenticated users to gain root access.
To fix CVE-1999-0080, reconfigure the wu-ftp FTP server to avoid using dangerous command paths in the _PATH_EXECPATH setting.
CVE-1999-0080 specifically affects wu-ftpd version 2.4.
The risk associated with CVE-1999-0080 includes unauthorized root access to the system by authenticated users.
Yes, CVE-1999-0080 can be exploited remotely by authenticated users through the 'site exec' command.