CuteFTP 'LIST' Command Directory Traversal Vulnerability
BID:29382
Info
CuteFTP 'LIST' Command Directory Traversal Vulnerability
| Bugtraq ID: | 29382 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 26 2008 12:00AM |
| Updated: | May 26 2008 12:00AM |
| Credit: | Tan Chew Keong |
| Vulnerable: |
globalSCAPE CuteFTP Pro 8.2 Build 04.01.2008.1 globalSCAPE CuteFTP Home 8.2 Build 02.26.2008.4 |
| Not Vulnerable: | |
Discussion
CuteFTP 'LIST' Command Directory Traversal Vulnerability
CuteFTP is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting this issue allows an attacker to write arbitrary files to locations outside of the FTP client's current directory. This could help the attacker launch further attacks.
The following CuteFTP versions are vulnerable:
CuteFTP Home 8.2.0 Build 02.26.2008.4
CuteFTP Pro 8.2.0 Build 04.01.2008.1
CuteFTP is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting this issue allows an attacker to write arbitrary files to locations outside of the FTP client's current directory. This could help the attacker launch further attacks.
The following CuteFTP versions are vulnerable:
CuteFTP Home 8.2.0 Build 02.26.2008.4
CuteFTP Pro 8.2.0 Build 04.01.2008.1
Exploit / POC
CuteFTP 'LIST' Command Directory Traversal Vulnerability
The researcher who discovered this issue has developed a working proof of concept, but it is not publicly available.
The researcher who discovered this issue has developed a working proof of concept, but it is not publicly available.
Solution / Fix
CuteFTP 'LIST' Command Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
CuteFTP 'LIST' Command Directory Traversal Vulnerability
References:
References:
- CuteFTP FTP Client Directory Traversal Vulnerability (Tan Chew Keong)
- CuteFTP Product Page (globalSCAPE)