ID

VAR-201006-0506


TITLE

Sysax Multi Server 'SFTP' Module Denial of Service Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2010-1148

DESCRIPTION

Sysax Multi Server is an SSH2 and FTP server for Windows. There are multiple denial of service problems in the Sysax Multi Server SFTP module. Unsafe commands include \"open\", \"unlink\", \"mkdir\", etc., and long strings are not handled correctly. An attacker with valid login credentials can exploit these issues to cause the server to crash, resulting in a denial-of-service condition. Other attacks may also be possible. Sysax Multi Server 5.25 is vulnerable; prior versions may also be affected. Update (June 28, 2010): Assuming the server is running as 'admin', attackers can execute arbitrary code to compromise the application

Trust: 0.81

sources: CNVD: CNVD-2010-1148 // BID: 41013

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2010-1148

AFFECTED PRODUCTS

vendor:nomodel: - scope: - version: -

Trust: 0.6

vendor:codeoriginmodel:sysax multi serverscope:eqversion:5.25

Trust: 0.3

vendor:codeoriginmodel:sysax multi serverscope:eqversion:4.3

Trust: 0.3

sources: CNVD: CNVD-2010-1148 // BID: 41013

THREAT TYPE

network

Trust: 0.3

sources: BID: 41013

TYPE

Input Validation Error

Trust: 0.3

sources: BID: 41013

EXTERNAL IDS

db:BIDid:41013

Trust: 0.9

db:CNVDid:CNVD-2010-1148

Trust: 0.6

sources: CNVD: CNVD-2010-1148 // BID: 41013

REFERENCES

url:http://www.securityfocus.com/archive/1/511911

Trust: 0.6

url:http://www.sysax.com/

Trust: 0.3

url:/archive/1/512046

Trust: 0.3

url:/archive/1/511911

Trust: 0.3

sources: CNVD: CNVD-2010-1148 // BID: 41013

CREDITS

leinakesi

Trust: 0.3

sources: BID: 41013

SOURCES

db:CNVDid:CNVD-2010-1148
db:BIDid:41013

LAST UPDATE DATE

2022-05-17T01:53:41.082000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2010-1148date:2010-06-22T00:00:00
db:BIDid:41013date:2010-06-28T17:28:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2010-1148date:2010-06-22T00:00:00
db:BIDid:41013date:2010-06-21T00:00:00