Null FTP Server 'SITE' Command Arbitrary Command Injection Vulnerability
BID:32656
Info
Null FTP Server 'SITE' Command Arbitrary Command Injection Vulnerability
| Bugtraq ID: | 32656 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 05 2008 12:00AM |
| Updated: | Dec 08 2008 11:11PM |
| Credit: | Tan Chew Keong |
| Vulnerable: |
VisionWorks Solutions NULL FTP Server 1.1.0.7 |
| Not Vulnerable: |
VisionWorks Solutions NULL FTP Server 1.1.0.8 |
Discussion
Null FTP Server 'SITE' Command Arbitrary Command Injection Vulnerability
Null FTP Server is prone to an arbitrary-command-injection vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker can exploit this issue to execute arbitrary commands in the context of the user running the application.
Null FTP Server 1.1.0.7 is vulnerable; prior versions may also be affected.
Null FTP Server is prone to an arbitrary-command-injection vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker can exploit this issue to execute arbitrary commands in the context of the user running the application.
Null FTP Server 1.1.0.7 is vulnerable; prior versions may also be affected.
Exploit / POC
Null FTP Server 'SITE' Command Arbitrary Command Injection Vulnerability
An attacker can use an FTP client to exploit this issue.
An attacker can use an FTP client to exploit this issue.
Solution / Fix
Null FTP Server 'SITE' Command Arbitrary Command Injection Vulnerability
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Solution:
The vendor released an update to address this issue. Please see the references for more information.
References
Null FTP Server 'SITE' Command Arbitrary Command Injection Vulnerability
References:
References:
- NULL FTP Server Homepage (VisionWorks Solutions)
- Null FTP Server Homepage (VisionWorks Solutions)
- NULL FTP Server SITE Parameters Command Injection Vulnerability (Tan Chew Keong)