WS_FTP Server Manager Authentication Bypass and Information Disclosure Vulnerabilities
BID:27654
Info
WS_FTP Server Manager Authentication Bypass and Information Disclosure Vulnerabilities
| Bugtraq ID: | 27654 |
| Class: | Unknown |
| CVE: |
CVE-2008-5693 CVE-2008-5692 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 06 2008 12:00AM |
| Updated: | Jul 06 2016 02:17PM |
| Credit: | Luigi Auriemma is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Ipswitch WS_FTP Server Manager 6.1.0.0 Ipswitch WS_FTP Server 6.1 .0 Ipswitch WS_FTP Server 6.0 |
| Not Vulnerable: |
Ipswitch WS_FTP Server 6.1.1 Ipswitch WS_FTP Server 7.1 |
Discussion
WS_FTP Server Manager Authentication Bypass and Information Disclosure Vulnerabilities
WS_FTP Server Manager is prone to an authentication-bypass vulnerability and an information-disclosure vulnerability.
An attacker can exploit these issues to gain unauthorized access to the affected application and gain access to potentially sensitive information.
These issues affect WS_FTP Server Manager 6.1.0.0; prior versions may also be affected.
WS_FTP Server Manager is prone to an authentication-bypass vulnerability and an information-disclosure vulnerability.
An attacker can exploit these issues to gain unauthorized access to the affected application and gain access to potentially sensitive information.
These issues affect WS_FTP Server Manager 6.1.0.0; prior versions may also be affected.
Exploit / POC
WS_FTP Server Manager Authentication Bypass and Information Disclosure Vulnerabilities
To exploit this issue, attackers can use a browser.
The following example URIs are available:
http://www.example.com/WSFTPSVR/FTPLogServer/login.asp?action=logLogout
http://www.example.com/WSFTPSVR/FTPLogServer/LogViewer.asp
http://www.example.com/WSFTPSVR/login.asp.
http://www.example.com/WSFTPSVR/FTPLogServer/LogViewer.asp.
http://www.example.com/WSFTPSVR/FTP/ViewCert.asp.
To exploit this issue, attackers can use a browser.
The following example URIs are available:
http://www.example.com/WSFTPSVR/FTPLogServer/login.asp?action=logLogout
http://www.example.com/WSFTPSVR/FTPLogServer/LogViewer.asp
http://www.example.com/WSFTPSVR/login.asp.
http://www.example.com/WSFTPSVR/FTPLogServer/LogViewer.asp.
http://www.example.com/WSFTPSVR/FTP/ViewCert.asp.
Solution / Fix
WS_FTP Server Manager Authentication Bypass and Information Disclosure Vulnerabilities
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
WS_FTP Server Manager Authentication Bypass and Information Disclosure Vulnerabilities
References:
References:
- WS FTP Homepage (IpSwitch)
- Logs visualization in WS_FTP Server Manager 6.1.0.0 (Luigi Auriemma
) - WS_FTP Server 6.1.1 with SSH & WS_FTP Server 6.1.1 (IpSwitch)