Intervations FileCopa FTP Server Directory Traversal Vulnerability
BID:16335
Info
Intervations FileCopa FTP Server Directory Traversal Vulnerability
| Bugtraq ID: | 16335 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 20 2006 12:00AM |
| Updated: | Feb 07 2006 08:55PM |
| Credit: | P@r@n01d and $um$id are credited with the discovery of this vulnerability. |
| Vulnerable: |
Intervations FileCopa FTP Server 1.01.-2005-11-21 |
| Not Vulnerable: |
Intervations FileCopa FTP Server 1.01.-2006-02-19 |
Discussion
Intervations FileCopa FTP Server Directory Traversal Vulnerability
Intervations FileCopa FTP Server is prone to a directory traversal vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to retrieve and overwrite arbitrary files in the context of the affected application. Depending on the files overwritten, this may facilitate a compromise of the underlying system; other attacks are also possible.
This issue affects version 1.01 which was released on 2005-11-21; other versions may also be vulnerable.
Intervations FileCopa FTP Server is prone to a directory traversal vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to retrieve and overwrite arbitrary files in the context of the affected application. Depending on the files overwritten, this may facilitate a compromise of the underlying system; other attacks are also possible.
This issue affects version 1.01 which was released on 2005-11-21; other versions may also be vulnerable.
Exploit / POC
Intervations FileCopa FTP Server Directory Traversal Vulnerability
This issue can be exploited manually. No exploit code is required.
This issue can be exploited manually. No exploit code is required.
Solution / Fix
Intervations FileCopa FTP Server Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
References
Intervations FileCopa FTP Server Directory Traversal Vulnerability
References:
References:
- Filecopa Download Page (Intervation)
- FileCopa FTP Directory Traversal Vulnerability (Network Intelligence)