Yak! Chat Client FTP Server Directory Traversal Vulnerability
BID:11433
Info
Yak! Chat Client FTP Server Directory Traversal Vulnerability
| Bugtraq ID: | 11433 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 15 2004 12:00AM |
| Updated: | Oct 15 2004 12:00AM |
| Credit: | Discovery is credited to Luigi Auriemma <[email protected]>. |
| Vulnerable: |
Digicraft Software Yak! 2.1.2 Digicraft Software Yak! 2.1.1 Digicraft Software Yak! 2.1 .0 Digicraft Software Yak! 2.0.2 Digicraft Software Yak! 2.0.1 Digicraft Software Yak! 2.0 |
| Not Vulnerable: | |
Discussion
Yak! Chat Client FTP Server Directory Traversal Vulnerability
Yak! Chat Client FTP server is reported prone to a remote directory traversal vulnerability. This issue presents itself due to insufficient sanitization of user-supplied data.
This issue can ultimately allow an attacker to compromise a computer by placing malicious files on the system and executing these files through other means.
Yak! 2.1.2 and prior versions are reported vulnerable to this issue.
Yak! Chat Client FTP server is reported prone to a remote directory traversal vulnerability. This issue presents itself due to insufficient sanitization of user-supplied data.
This issue can ultimately allow an attacker to compromise a computer by placing malicious files on the system and executing these files through other means.
Yak! 2.1.2 and prior versions are reported vulnerable to this issue.
Exploit / POC
Yak! Chat Client FTP Server Directory Traversal Vulnerability
An exploit is not required.
The following proof of concept is available:
dir /
dir ../../windows/
put
evil.exe
../../windows/calc.exe
An exploit is not required.
The following proof of concept is available:
dir /
dir ../../windows/
put
evil.exe
../../windows/calc.exe
Solution / Fix
Yak! Chat Client FTP Server Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Yak! Chat Client FTP Server Directory Traversal Vulnerability
References:
References:
- Yak! Product Page (Digicraft Software)
- Directory traversal in Yak! 2.1.2 (Luigi Auriemma
)