Serv-U FTP Directory Traversal Vulnerability
BID:2052
Info
Serv-U FTP Directory Traversal Vulnerability
| Bugtraq ID: | 2052 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Dec 05 2000 12:00AM |
| Updated: | Dec 05 2000 12:00AM |
| Credit: | Discovered and posted to Bugtraq by Zoa_Chien <[email protected]> on Dec 5, 2000. |
| Vulnerable: |
Cat Soft Serv-U 2.5 Cat Soft Serv-U 2.4 |
| Not Vulnerable: |
Cat Soft Serv-U 2.5 i |
Discussion
Serv-U FTP Directory Traversal Vulnerability
FTP Serv-U is an internet FTP server from CatSoft.
Authenticated users can gain access to the ftproot of the drive where Serv-U FTP has been installed. Users that have read, write, execute and list access in the home directory will have the same permissions to any file which resides on the same partition as the ftproot, once a user is in the home directory they can successfully transfer any files using specially crafted GET requests. All hidden files will be revealed even if the 'Hide hidden files' feature is on.
Successful exploitation of this vulnerability could enable a remote user to gain access to systems files, password files, etc. This could lead to a complete compromise of the host.
FTP Serv-U is an internet FTP server from CatSoft.
Authenticated users can gain access to the ftproot of the drive where Serv-U FTP has been installed. Users that have read, write, execute and list access in the home directory will have the same permissions to any file which resides on the same partition as the ftproot, once a user is in the home directory they can successfully transfer any files using specially crafted GET requests. All hidden files will be revealed even if the 'Hide hidden files' feature is on.
Successful exploitation of this vulnerability could enable a remote user to gain access to systems files, password files, etc. This could lead to a complete compromise of the host.