WFTPD Shortcut Directory Traversal Vulnerability
BID:2957
Info
WFTPD Shortcut Directory Traversal Vulnerability
| Bugtraq ID: | 2957 |
| Class: | Input Validation Error |
| CVE: |
CVE-2001-1386 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 01 2001 12:00AM |
| Updated: | Jul 11 2009 06:56AM |
| Credit: | Reported to Bugtraq by ByteRage <[email protected]> on July 1, 2001. |
| Vulnerable: |
Texas Imperial Software WFTPD 3.0 Pro Texas Imperial Software WFTPD 3.0 0R5 Pro Texas Imperial Software WFTPD 3.0 0R5 Texas Imperial Software WFTPD 3.0 0R4 Pro Texas Imperial Software WFTPD 3.0 0R4 Texas Imperial Software WFTPD 3.0 0R3 Texas Imperial Software WFTPD 3.0 Texas Imperial Software WFTPD 2.41 RC14 Pro Texas Imperial Software WFTPD 2.41 RC14 Texas Imperial Software WFTPD 2.40 Texas Imperial Software WFTPD 2.4.1 RC12 Texas Imperial Software WFTPD 2.4.1 RC11 Texas Imperial Software WFTPD 2.4.1 |
| Not Vulnerable: |
Texas Imperial Software WFTPD Pro 3.10 R1 Texas Imperial Software WFTPD 3.10 R1 |
Discussion
WFTPD Shortcut Directory Traversal Vulnerability
WFTPD is a popular FTP server software for Windows systems.
The WFTPD server contains a directory traversal vulnerability. It may be possible for remote users to upload files with the filename extension '.LNK.', thereby creating shortcuts to otherwise protected files and directories.
WFTPD is a popular FTP server software for Windows systems.
The WFTPD server contains a directory traversal vulnerability. It may be possible for remote users to upload files with the filename extension '.LNK.', thereby creating shortcuts to otherwise protected files and directories.
Exploit / POC
WFTPD Shortcut Directory Traversal Vulnerability
Create a Windows shortcut file (*.lnk) that points to the desired directory on the target system. Upload the file to the target with the filename extension '.LNK.', and enter a change directory command specifying the name of the .lnk file as the argument.
Create a Windows shortcut file (*.lnk) that points to the desired directory on the target system. Upload the file to the target with the filename extension '.LNK.', and enter a change directory command specifying the name of the .lnk file as the argument.
References
WFTPD Shortcut Directory Traversal Vulnerability
References:
References: