CVE-2020-8284

CVE-2020-8284

A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions.

Source: CVE-2020-8284

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다