Transoft Broker .lnk Directory Traversal Vulnerability
BID:2960
Info
Transoft Broker .lnk Directory Traversal Vulnerability
| Bugtraq ID: | 2960 |
| Class: | Access Validation Error |
| CVE: |
CVE-2001-1042 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 02 2001 12:00AM |
| Updated: | Jul 11 2009 06:56AM |
| Credit: | Posted to the bugtraq mailing list on July 2, 2001 by ByteRage <[email protected]>. |
| Vulnerable: |
TransSoft Broker FTP Server 5.9.5 .0 TransSoft Broker FTP Server 5.7.5 TransSoft Broker FTP Server 5.7 TransSoft Broker FTP Server 5.1 TransSoft Broker FTP Server 5.0 TransSoft Broker FTP Server 4.7 .5.0 TransSoft Broker FTP Server 4.0 TransSoft Broker FTP Server 3.0 x TransSoft Broker FTP Server 3.0 Build 1 |
| Not Vulnerable: | |
Exploit / POC
Transoft Broker .lnk Directory Traversal Vulnerability
Create a Windows shortcut file (*.lnk) that points to the desired directory on the target system. Upload the file to the target, and enter a cd command specifying the name of the .lnk file as the argument.
Create a Windows shortcut file (*.lnk) that points to the desired directory on the target system. Upload the file to the target, and enter a cd command specifying the name of the .lnk file as the argument.
Solution / Fix
Transoft Broker .lnk Directory Traversal Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.