Vulnerabilities > CVE-2007-6738 - Unspecified vulnerability in G.Rodola Pyftpdlib

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
g-rodola

Summary

pyftpdlib before 0.1.1 does not choose a random value for the port associated with the PASV command, which makes it easier for remote attackers to obtain potentially sensitive information about the number of in-progress data connections by reading the response to this command.

Vulnerable Configurations

Part Description Count
Application
G.Rodola
1