FileCOPA FTP Server Directory Traversal Vulnerability
BID:40312
Info
FileCOPA FTP Server Directory Traversal Vulnerability
| Bugtraq ID: | 40312 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 21 2010 12:00AM |
| Updated: | May 21 2010 12:00AM |
| Credit: | Sow Ching Shiong |
| Vulnerable: |
Intervations FileCopa FTP Server 5.02 |
| Not Vulnerable: |
Intervations FileCopa FTP Server 5.03 |
Discussion
FileCOPA FTP Server Directory Traversal Vulnerability
FileCOPA FTP Server is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue can allow an attacker to download or upload arbitrary files outside of the FTP server root directory. This may aid in further attacks.
FileCOPA FTP Server 5.02 is affected; other versions may also be vulnerable.
FileCOPA FTP Server is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue can allow an attacker to download or upload arbitrary files outside of the FTP server root directory. This may aid in further attacks.
FileCOPA FTP Server 5.02 is affected; other versions may also be vulnerable.
Exploit / POC
FileCOPA FTP Server Directory Traversal Vulnerability
Attackers can use readily available tools and commands to exploit this issue.
Attackers can use readily available tools and commands to exploit this issue.
Solution / Fix
FileCOPA FTP Server Directory Traversal Vulnerability
Solution:
Reportedly the issue is fixed in version 5.03 but this has not been confirmed. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed in version 5.03 but this has not been confirmed. Please contact the vendor for more information.