Small HTTP server FTP Directory Traversal Vulnerability
BID:33570
Info
Small HTTP server FTP Directory Traversal Vulnerability
| Bugtraq ID: | 33570 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 02 2009 12:00AM |
| Updated: | Feb 04 2009 12:09AM |
| Credit: | Houssamix |
| Vulnerable: |
Max Feoktistov Small HTTP server 3.5.84 |
| Not Vulnerable: | |
Discussion
Small HTTP server FTP Directory Traversal Vulnerability
'Small HTTP server' is prone to a directory-traversal vulnerability because the application fails to sufficiently sanitize user-supplied input.
Exploiting this issue will allow an attacker to view arbitrary directories within the context of the webserver. Information harvested may aid in launching further attacks.
This issue affect Small HTTP server 3.05.84; other versions may also be affected.
'Small HTTP server' is prone to a directory-traversal vulnerability because the application fails to sufficiently sanitize user-supplied input.
Exploiting this issue will allow an attacker to view arbitrary directories within the context of the webserver. Information harvested may aid in launching further attacks.
This issue affect Small HTTP server 3.05.84; other versions may also be affected.
Exploit / POC
Small HTTP server FTP Directory Traversal Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
Small HTTP server FTP Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Small HTTP server FTP Directory Traversal Vulnerability
References:
References:
- Small FTP Server Homepage (Houssamix)