Gene 6 BPFTP Server Path Disclosure Vulnerability
BID:2693
Info
Gene 6 BPFTP Server Path Disclosure Vulnerability
| Bugtraq ID: | 2693 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 17 2001 12:00AM |
| Updated: | Feb 17 2001 12:00AM |
| Credit: | Posted to Bugtraq by Tom Tom <[email protected]> on May 6, 2001 and discovered by t-Omicr0n <[email protected]> on February 17, 2001. |
| Vulnerable: |
Gene6 BPFTP Server 2.0 |
| Not Vulnerable: | |
Discussion
Gene 6 BPFTP Server Path Disclosure Vulnerability
G6 FTP Server now known as BPFTP Server is an internet FTP server by Gene6
BPFTP Server has a flaw which can permit a remote user to learn the physcial path to the FTP service's root directory.
By submitting the FTP command 'dele' along with ':' and any filename, the attacker can cause an error message to be generated by BPFTP which includes the path for the ftp root.
Properly exploited, this information could assist a hostile user in carrying out other attacks on the system.
G6 FTP Server now known as BPFTP Server is an internet FTP server by Gene6
BPFTP Server has a flaw which can permit a remote user to learn the physcial path to the FTP service's root directory.
By submitting the FTP command 'dele' along with ':' and any filename, the attacker can cause an error message to be generated by BPFTP which includes the path for the ftp root.
Properly exploited, this information could assist a hostile user in carrying out other attacks on the system.
Exploit / POC
Gene 6 BPFTP Server Path Disclosure Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Gene 6 BPFTP Server Path Disclosure Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.