Fastream NetFile FTP/Web Server Directory Traversal Vulnerability
BID:10658
Info
Fastream NetFile FTP/Web Server Directory Traversal Vulnerability
| Bugtraq ID: | 10658 |
| Class: | Input Validation Error |
| CVE: |
CVE-2004-0676 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 05 2004 12:00AM |
| Updated: | Jul 12 2009 06:16AM |
| Credit: | Discovery is credited to Andres Tarasco Acuna <[email protected]>. |
| Vulnerable: |
Fastream NetFILE FTP/Web Server 6.7.2 .1085 Fastream NetFILE FTP/Web Server 6.5.1 .981 Fastream NetFILE FTP/Web Server 6.5.1 .980 |
| Not Vulnerable: |
Fastream NetFILE FTP/Web Server 6.7.5 Fastream NetFILE FTP/Web Server 6.7.3 |
Discussion
Fastream NetFile FTP/Web Server Directory Traversal Vulnerability
The NetFile FTP/Web Server is reported prone to a directory traversal vulnerability due to insufficient sanitization of user-supplied data. This can allow an attacker to create, view, and delete arbitrary files outside the web root.
Fastream NetFILE FTP/Web Server versions 6.7.2.1085 and prior are reported prone to this issue.
The NetFile FTP/Web Server is reported prone to a directory traversal vulnerability due to insufficient sanitization of user-supplied data. This can allow an attacker to create, view, and delete arbitrary files outside the web root.
Fastream NetFILE FTP/Web Server versions 6.7.2.1085 and prior are reported prone to this issue.
Exploit / POC
Fastream NetFile FTP/Web Server Directory Traversal Vulnerability
No exploit is required.
The following proof of concept is available:
http://www.example.com?command=mkdir&filename=..//FOLDER_IS_OUTSIDE_THE_ROOT_DIRECTORY
No exploit is required.
The following proof of concept is available:
http://www.example.com?command=mkdir&filename=..//FOLDER_IS_OUTSIDE_THE_ROOT_DIRECTORY
Solution / Fix
Fastream NetFile FTP/Web Server Directory Traversal Vulnerability
Solution:
The vendor has released new versions to address this issue.
Fastream NetFILE FTP/Web Server 6.5.1 .981
Fastream NetFILE FTP/Web Server 6.5.1 .980
Fastream NetFILE FTP/Web Server 6.7.2 .1085
Solution:
The vendor has released new versions to address this issue.
Fastream NetFILE FTP/Web Server 6.5.1 .981
-
Fastream NetFILE FTP/Web Server 6.7.5
http://www.fastream.com/netfileserver.htm#license
Fastream NetFILE FTP/Web Server 6.5.1 .980
-
Fastream NetFILE FTP/Web Server 6.7.5
http://www.fastream.com/netfileserver.htm#license
Fastream NetFILE FTP/Web Server 6.7.2 .1085
-
Fastream NetFILE FTP/Web Server 6.7.5
http://www.fastream.com/netfileserver.htm#license
References
Fastream NetFile FTP/Web Server Directory Traversal Vulnerability
References:
References:
- Fastream NETFile FTP/Web Server (Fastream)
- Fastream NETFile FTP/Web Server Input validation Errors ("at4r"
)