Pi-Soft SpoonFTP Directory Traversal Vulnerability
BID:3351
Info
Pi-Soft SpoonFTP Directory Traversal Vulnerability
| Bugtraq ID: | 3351 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 20 2001 12:00AM |
| Updated: | Sep 20 2001 12:00AM |
| Credit: | Discovered and posted to Bugtraq by [email protected] on Sep 20, 2001. |
| Vulnerable: |
Pi-Soft SpoonFTP 1.1 |
| Not Vulnerable: |
Pi-Soft SpoonFTP 1.0 .1 |
Discussion
Pi-Soft SpoonFTP Directory Traversal Vulnerability
A vulnerability exists in SpoonFTP Server which allows a remote user to traverse the directories of a target host. This may lead to the disclosure of file and directory contents. Arbitrary directories can be accessed through the use of triple dot '...' sequence when using the 'cd' command.
A vulnerability exists in SpoonFTP Server which allows a remote user to traverse the directories of a target host. This may lead to the disclosure of file and directory contents. Arbitrary directories can be accessed through the use of triple dot '...' sequence when using the 'cd' command.
Exploit / POC
Pi-Soft SpoonFTP Directory Traversal Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Pi-Soft SpoonFTP Directory Traversal Vulnerability
Solution:
The vendor has addressed this issue in SpoonFTP 1.1.0.1:
Pi-Soft SpoonFTP 1.1
Solution:
The vendor has addressed this issue in SpoonFTP 1.1.0.1:
Pi-Soft SpoonFTP 1.1
-
Pi-Soft SpoonFTP1.1.0.1
http://www.pi-soft.com/spoonftp/sftp.exe