net2ftp FTP Client Request Archive Handling Directory Traversal Vulnerability
BID:29664
Info
net2ftp FTP Client Request Archive Handling Directory Traversal Vulnerability
| Bugtraq ID: | 29664 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-5275 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 11 2008 12:00AM |
| Updated: | Dec 01 2008 11:53PM |
| Credit: | Tan Chew Keong |
| Vulnerable: |
net2ftp net2ftp 0.97 (beta) net2ftp net2ftp 0.96 (stable) net2ftp net2ftp 0.93 |
| Not Vulnerable: |
net2ftp net2ftp 0.97 (stable) |
Discussion
net2ftp FTP Client Request Archive Handling Directory Traversal Vulnerability
The 'net2ftp' program is prone to a vulnerability that can allow remote attackers to retrieve or delete files or to run arbitrary PHP code.
A successful exploit can allow an attacker to upload arbitrary PHP scripts and run them in the context of the application, obtain sensitive information, or delete files. Other attacks may also be possible.
This issue affects net2ftp 0.96 (stable) and 0.97 (beta); other versions may also be affected.
The 'net2ftp' program is prone to a vulnerability that can allow remote attackers to retrieve or delete files or to run arbitrary PHP code.
A successful exploit can allow an attacker to upload arbitrary PHP scripts and run them in the context of the application, obtain sensitive information, or delete files. Other attacks may also be possible.
This issue affects net2ftp 0.96 (stable) and 0.97 (beta); other versions may also be affected.
Exploit / POC
net2ftp FTP Client Request Archive Handling Directory Traversal Vulnerability
Attackers can use readily available tools to exploit this issue.
Attackers can use readily available tools to exploit this issue.
Solution / Fix
net2ftp FTP Client Request Archive Handling Directory Traversal Vulnerability
Solution:
The vendor has released net2ftp 0.97 (stable) to address this issue. Please see the references for more information.
net2ftp net2ftp 0.93
net2ftp net2ftp 0.96 (stable)
net2ftp net2ftp 0.97 (beta)
Solution:
The vendor has released net2ftp 0.97 (stable) to address this issue. Please see the references for more information.
net2ftp net2ftp 0.93
-
net2ftp net2ftp_v0.97.zip
http://www.net2ftp.com/download/net2ftp_v0.97.zip
net2ftp net2ftp 0.96 (stable)
-
net2ftp net2ftp_v0.97.zip
http://www.net2ftp.com/download/net2ftp_v0.97.zip
net2ftp net2ftp 0.97 (beta)
-
net2ftp net2ftp_v0.97.zip
http://www.net2ftp.com/download/net2ftp_v0.97.zip
References
net2ftp FTP Client Request Archive Handling Directory Traversal Vulnerability
References:
References:
- NET2FTP CHANGELOG (net2ftp)
- net2ftp Homepage (net2ftp)
- net2ftp Web-based FTP-Client Request Handling Vulnerability (Tan Chew Keong)