ArGoSoft FTP Server Site Copy Shortcut File Upload Vulnerability
BID:12632
Info
ArGoSoft FTP Server Site Copy Shortcut File Upload Vulnerability
| Bugtraq ID: | 12632 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 23 2005 12:00AM |
| Updated: | Feb 23 2005 12:00AM |
| Credit: | This vulnerability was discovered by Cirpian Radu. |
| Vulnerable: |
ArGo Software Design FTP Server 1.4.2 .7 ArGo Software Design FTP Server 1.4.2 .2 ArGo Software Design FTP Server 1.4.2 .1 ArGo Software Design FTP Server 1.4.2 .0 ArGo Software Design FTP Server 1.4.1 .9 ArGo Software Design FTP Server 1.4.1 .8 ArGo Software Design FTP Server 1.4.1 .7 ArGo Software Design FTP Server 1.4.1 .6 ArGo Software Design FTP Server 1.4.1 .5 ArGo Software Design FTP Server 1.4.1 .4 ArGo Software Design FTP Server 1.4.1 .3 ArGo Software Design FTP Server 1.4.1 .2 ArGo Software Design FTP Server 1.4.1 .1 ArGo Software Design FTP Server 1.2.2 .2 ArGo Software Design FTP Server 1.0 |
| Not Vulnerable: |
ArGo Software Design FTP Server 1.4.2.8 |
Discussion
ArGoSoft FTP Server Site Copy Shortcut File Upload Vulnerability
ArGoSoft FTP server is reported prone to a vulnerability that allows users to upload shortcut (.lnk) files to the server.
It is conjectured that this issue is related to BID 2961 (ArGoSoft FTP Server .lnk Directory Traversal Vulnerability), which allows users with write permission to any directory to create and upload a .lnk file that points to the directory of their choice.
ArGoSoft FTP server 1.4.2.7 and prior versions are reportedly affected by this issue.
ArGoSoft FTP server is reported prone to a vulnerability that allows users to upload shortcut (.lnk) files to the server.
It is conjectured that this issue is related to BID 2961 (ArGoSoft FTP Server .lnk Directory Traversal Vulnerability), which allows users with write permission to any directory to create and upload a .lnk file that points to the directory of their choice.
ArGoSoft FTP server 1.4.2.7 and prior versions are reportedly affected by this issue.
Exploit / POC
ArGoSoft FTP Server Site Copy Shortcut File Upload Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
ArGoSoft FTP Server Site Copy Shortcut File Upload Vulnerability
Solution:
The vendor has released an update to address this vulnerability:
ArGo Software Design FTP Server 1.0
ArGo Software Design FTP Server 1.2.2 .2
ArGo Software Design FTP Server 1.4.1 .4
ArGo Software Design FTP Server 1.4.1 .2
ArGo Software Design FTP Server 1.4.1 .8
ArGo Software Design FTP Server 1.4.1 .5
ArGo Software Design FTP Server 1.4.1 .9
ArGo Software Design FTP Server 1.4.1 .6
ArGo Software Design FTP Server 1.4.1 .3
ArGo Software Design FTP Server 1.4.1 .1
ArGo Software Design FTP Server 1.4.1 .7
ArGo Software Design FTP Server 1.4.2 .2
ArGo Software Design FTP Server 1.4.2 .1
ArGo Software Design FTP Server 1.4.2 .0
ArGo Software Design FTP Server 1.4.2 .7
Solution:
The vendor has released an update to address this vulnerability:
ArGo Software Design FTP Server 1.0
-
ArGoSoft FTP Server Version 1.4.2.8
http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe
ArGo Software Design FTP Server 1.2.2 .2
-
ArGoSoft FTP Server Version 1.4.2.8
http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe
ArGo Software Design FTP Server 1.4.1 .4
-
ArGoSoft FTP Server Version 1.4.2.8
http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe
ArGo Software Design FTP Server 1.4.1 .2
-
ArGoSoft FTP Server Version 1.4.2.8
http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe
ArGo Software Design FTP Server 1.4.1 .8
-
ArGoSoft FTP Server Version 1.4.2.8
http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe
ArGo Software Design FTP Server 1.4.1 .5
-
ArGoSoft FTP Server Version 1.4.2.8
http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe
ArGo Software Design FTP Server 1.4.1 .9
-
ArGoSoft FTP Server Version 1.4.2.8
http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe
ArGo Software Design FTP Server 1.4.1 .6
-
ArGoSoft FTP Server Version 1.4.2.8
http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe
ArGo Software Design FTP Server 1.4.1 .3
-
ArGoSoft FTP Server Version 1.4.2.8
http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe
ArGo Software Design FTP Server 1.4.1 .1
-
ArGoSoft FTP Server Version 1.4.2.8
http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe
ArGo Software Design FTP Server 1.4.1 .7
-
ArGoSoft FTP Server Version 1.4.2.8
http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe
ArGo Software Design FTP Server 1.4.2 .2
-
ArGoSoft FTP Server Version 1.4.2.8
http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe
ArGo Software Design FTP Server 1.4.2 .1
-
ArGoSoft FTP Server Version 1.4.2.8
http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe
ArGo Software Design FTP Server 1.4.2 .0
-
ArGoSoft FTP Server Version 1.4.2.8
http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe
ArGo Software Design FTP Server 1.4.2 .7
-
ArGoSoft FTP Server Version 1.4.2.8
http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe
References
ArGoSoft FTP Server Site Copy Shortcut File Upload Vulnerability
References:
References:
- ArGoSoft FTP Server Change List (ArGoSoft)