TransSoft Broker FTP Server Directory Traversal Vulnerability
BID:2853
Info
TransSoft Broker FTP Server Directory Traversal Vulnerability
| Bugtraq ID: | 2853 |
| Class: | Input Validation Error |
| CVE: |
CVE-2001-0687 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 10 2001 12:00AM |
| Updated: | Jul 11 2009 06:56AM |
| Credit: | Reported to bugtraq by ByteRage <[email protected]> on June 10, 2001. |
| Vulnerable: |
TransSoft Broker FTP Server 5.9.5 .0 TransSoft Broker FTP Server 5.7 TransSoft Broker FTP Server 5.1 TransSoft Broker FTP Server 5.0 TransSoft Broker FTP Server 4.7 .5.0 TransSoft Broker FTP Server 4.0 |
| Not Vulnerable: | |
Discussion
TransSoft Broker FTP Server Directory Traversal Vulnerability
Broker is a Windows FTP server from TransSoft.
Versions of Broker are vulnerable to directory traversals.
The server fails to restrict a remote user's navigation of the host filesystem. By submitting a CD command argumented with a valid MS DOS drive letter (ie CD C:) a user can use an FTP client to inspect the contents of arbitrary directories on the server. Floppy drives (A:) and CD ROM volumes are similarly accessible. An LS command will list the contents of any directory reached in this way.
This bug also permits the remote user to specify arbitrary paths in UNC format, ie \\computername\sharename, where computername = the NetBIOS name of the computer, and sharename = the share name of the folder.
An attacker could use this knowledge of the host's filesystem to exploit other possible vulnerabilities and further compromise the target system.
Broker is a Windows FTP server from TransSoft.
Versions of Broker are vulnerable to directory traversals.
The server fails to restrict a remote user's navigation of the host filesystem. By submitting a CD command argumented with a valid MS DOS drive letter (ie CD C:) a user can use an FTP client to inspect the contents of arbitrary directories on the server. Floppy drives (A:) and CD ROM volumes are similarly accessible. An LS command will list the contents of any directory reached in this way.
This bug also permits the remote user to specify arbitrary paths in UNC format, ie \\computername\sharename, where computername = the NetBIOS name of the computer, and sharename = the share name of the folder.
An attacker could use this knowledge of the host's filesystem to exploit other possible vulnerabilities and further compromise the target system.
Exploit / POC
TransSoft Broker FTP Server Directory Traversal Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
TransSoft Broker FTP Server Directory Traversal Vulnerability
References:
References:
- Broker FTP Server (TransSoft)