« Volver al listado

CVE-2002-0139

Estado: ModificadaAlta (7.5)—

Pi-Soft SpoonFTP 1.1 and earlier allows remote attackers to redirect traffic to other sites (aka FTP bounce) via the PORT command.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2002-0139",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": true,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2002-03-25T05:00:00.000",
  "references": [
    {
      "url": "http://online.securityfocus.com/archive/1/251422",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.iss.net/security_center/static/7943.php",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.pi-soft.com/spoonftp/index.shtml",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/3910",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://online.securityfocus.com/archive/1/251422",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.iss.net/security_center/static/7943.php",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.pi-soft.com/spoonftp/index.shtml",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/3910",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Pi-Soft SpoonFTP 1.1 and earlier allows remote attackers to redirect traffic to other sites (aka FTP bounce) via the PORT command."
    },
    {
      "lang": "es",
      "value": "Pi-Soft SpoonFTP 1.1 y versiones anteriores permiten a atacantes remotos redirigir el tráfico de datos a otros sitios (también conocido como 'rebote' FTP) mediante el uso del comando PORT."
    }
  ],
  "lastModified": "2026-06-16T21:56:52.317",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:pi-soft:spoonftp:0.01.1.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1E81FE55-CB7F-4E07-B7AA-455EDE663731"
            },
            {
              "criteria": "cpe:2.3:a:pi-soft:spoonftp:1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BE968F81-AE1B-4FFE-9518-14D2713286F1"
            },
            {
              "criteria": "cpe:2.3:a:pi-soft:spoonftp:1.00.12:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A60B805D-0A1E-436A-AFB1-1D5054B0A3BF"
            },
            {
              "criteria": "cpe:2.3:a:pi-soft:spoonftp:1.00.13:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "76CC5152-9028-4E4A-8FE1-A38480E4098C"
            },
            {
              "criteria": "cpe:2.3:a:pi-soft:spoonftp:1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DABC0B8B-C6AE-49B8-9C0E-56E65FC26CD4"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}