GuildFTPd 'DELE' Command Security Bypass Vulnerability
BID:34079
Info
GuildFTPd 'DELE' Command Security Bypass Vulnerability
| Bugtraq ID: | 34079 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 10 2009 12:00AM |
| Updated: | Mar 12 2009 05:36PM |
| Credit: | Jonathan Salwan |
| Vulnerable: |
GuildFTPd GuildFTPd 0.999.14 |
| Not Vulnerable: | |
Discussion
GuildFTPd 'DELE' Command Security Bypass Vulnerability
GuildFTPd is prone to a security-bypass vulnerability.
Remote attackers can exploit this issue to bypass certain security restrictions and carry out unauthorized tasks.
This issue affects GuildFTPd 0.999.14. Other versions may also be vulnerable.
GuildFTPd is prone to a security-bypass vulnerability.
Remote attackers can exploit this issue to bypass certain security restrictions and carry out unauthorized tasks.
This issue affects GuildFTPd 0.999.14. Other versions may also be vulnerable.
Exploit / POC
GuildFTPd 'DELE' Command Security Bypass Vulnerability
An attacker may exploit this issue using an FTP client.
The following exploit is available:
An attacker may exploit this issue using an FTP client.
The following exploit is available:
Solution / Fix
GuildFTPd 'DELE' Command Security Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].