CesarFTP Directory Traversal Vulnerability
BID:2786
Info
CesarFTP Directory Traversal Vulnerability
| Bugtraq ID: | 2786 |
| Class: | Input Validation Error |
| CVE: |
CVE-2001-1335 |
| Remote: | Yes |
| Local: | No |
| Published: | May 27 2001 12:00AM |
| Updated: | Jul 11 2009 06:06AM |
| Credit: | This vulnerability was posted to BugTraq on May 27th, 2001 by ByteRage <[email protected]>. |
| Vulnerable: |
ACLogic CesarFTP 0.98 b |
| Not Vulnerable: | |
Discussion
CesarFTP Directory Traversal Vulnerability
CesarFTP is a freely available FTP Server for Microsoft Windows 9x/ME systems.
CesarFTP on Windows 98/Me platforms contains a 'directory traversal' vulnerability.
If a user requests to change directories to "..." from within a mapped directory, they will change into the directory above the 'real' directory on the filesystem. At this point they can traverse the filesystem and will have read access to almost every file.
A user must already have an account on the server to take advantage of this vulnerability.
Note: This vulnerability only affects Windows 98/Me systems running CesarFTP.
CesarFTP is a freely available FTP Server for Microsoft Windows 9x/ME systems.
CesarFTP on Windows 98/Me platforms contains a 'directory traversal' vulnerability.
If a user requests to change directories to "..." from within a mapped directory, they will change into the directory above the 'real' directory on the filesystem. At this point they can traverse the filesystem and will have read access to almost every file.
A user must already have an account on the server to take advantage of this vulnerability.
Note: This vulnerability only affects Windows 98/Me systems running CesarFTP.
Solution / Fix
CesarFTP Directory Traversal Vulnerability
Solution:
The vendor has been notified, but as of yet has not responded with news of any pending patches or fixes.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
The vendor has been notified, but as of yet has not responded with news of any pending patches or fixes.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.