CVE-2017-15270

CVE-2017-15270

The PSFTPd 10.0.4 Build 729 server does not properly escape data before writing it into a Comma Separated Values (CSV) file. This can be used by attackers to hide data in the Graphical User Interface (GUI) view and create arbitrary entries to a certain extent. Special characters such as ‘"’ and ‘,’ and ‘r’ are not escaped and can be used to add new entries to the log.

Source: CVE-2017-15270

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다