Shuttle FTP Suite TFTP Server Directory Traversal Vulnerability
BID:10916
Info
Shuttle FTP Suite TFTP Server Directory Traversal Vulnerability
| Bugtraq ID: | 10916 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 11 2004 12:00AM |
| Updated: | Aug 11 2004 12:00AM |
| Credit: | Ziv Kamir disclosed this vulnerability. |
| Vulnerable: |
Xavier Cirac Shuttle FTP Suite 3.2 |
| Not Vulnerable: | |
Discussion
Shuttle FTP Suite TFTP Server Directory Traversal Vulnerability
It is reported that the Shuttle FTP Suite TFTP server is susceptible to a directory traversal vulnerability.
This vulnerability allows a remote attacker to read and write files outside of the TFTP document root directory. An attacker may read and write files with the privileges of the TFTP server process.
An attacker may retrieve or overwrite sensitive files on the hosting computer, potentially aiding them in further system compromise.
Version 3.2 has been reported susceptible to this vulnerability. Other versions may also be affected.
It is reported that the Shuttle FTP Suite TFTP server is susceptible to a directory traversal vulnerability.
This vulnerability allows a remote attacker to read and write files outside of the TFTP document root directory. An attacker may read and write files with the privileges of the TFTP server process.
An attacker may retrieve or overwrite sensitive files on the hosting computer, potentially aiding them in further system compromise.
Version 3.2 has been reported susceptible to this vulnerability. Other versions may also be affected.
Exploit / POC
Shuttle FTP Suite TFTP Server Directory Traversal Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Shuttle FTP Suite TFTP Server Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Shuttle FTP Suite TFTP Server Directory Traversal Vulnerability
References:
References:
- Shuttle FTP Suite Directory Traversal Vulnerability (Secunia)
- Shuttle FTP Suite Home Page (Xavier Cirac)