Netwin SurgeFTP Server Information Disclosure Vulnerability
BID:2892
Info
Netwin SurgeFTP Server Information Disclosure Vulnerability
| Bugtraq ID: | 2892 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 19 2001 12:00AM |
| Updated: | Jun 19 2001 12:00AM |
| Credit: | Reported to bugtraq by SDL Office <[email protected]> on June 19, 2001. |
| Vulnerable: |
NetWin SurgeFTP 2.0 a Win 95/98 NetWin SurgeFTP 1.0 b Win 95/98 |
| Not Vulnerable: |
NetWin SurgeFTP 2.0 b Win 95/98 |
Exploit / POC
Netwin SurgeFTP Server Information Disclosure Vulnerability
(courtesy SDL Office <[email protected]>):
Connect to the server with anonymous and type "nlist ..."
(courtesy SDL Office <[email protected]>):
Connect to the server with anonymous and type "nlist ..."
References
Netwin SurgeFTP Server Information Disclosure Vulnerability
References:
References:
- NetWin Homepage (NetWin Limited)