EFTP Server Directory and File Existence Vulnerability
BID:3333
Info
EFTP Server Directory and File Existence Vulnerability
| Bugtraq ID: | 3333 |
| Class: | Access Validation Error |
| CVE: |
CVE-2001-1109 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 12 2001 12:00AM |
| Updated: | Jul 11 2009 07:56AM |
| Credit: | Discovered and posted to Bugtraq by ByteRage <[email protected]> on Sep 12, 2001. |
| Vulnerable: |
Khamil Landross and Zack Jones EFTP 2.0.7 .337 |
| Not Vulnerable: | |
Discussion
EFTP Server Directory and File Existence Vulnerability
A user can confirm the existence and location of files and directory structure information, by submitting a 'size' or 'mdtm' command of a file. If the command is carried out by the vulnerable service, the attacker can confirm the location of the file.
Submitting a 'size' or 'mdtm' command for a file outside of the FTP root could disclose directory structure information of unpublished filesystems on the host. If the requested command is fulfilled by the vulnerable service, the attacker can confirm the relative path to the file.
A user can confirm the existence and location of files and directory structure information, by submitting a 'size' or 'mdtm' command of a file. If the command is carried out by the vulnerable service, the attacker can confirm the location of the file.
Submitting a 'size' or 'mdtm' command for a file outside of the FTP root could disclose directory structure information of unpublished filesystems on the host. If the requested command is fulfilled by the vulnerable service, the attacker can confirm the relative path to the file.
Exploit / POC
EFTP Server Directory and File Existence Vulnerability
ByteRage <[email protected]> has provided the following exploit:
ByteRage <[email protected]> has provided the following exploit:
Solution / Fix
EFTP Server Directory and File Existence Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
EFTP Server Directory and File Existence Vulnerability
References:
References:
- EFTP Main Page (Khamil Landross and Zack Jones)