SnugServer FTP Directory Traversal Vulnerability
BID:40313
Info
SnugServer FTP Directory Traversal Vulnerability
| Bugtraq ID: | 40313 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 21 2010 12:00AM |
| Updated: | May 21 2010 12:00AM |
| Credit: | Sow Ching Shiong |
| Vulnerable: |
SnugServer SnugServer 4.3.0.126 |
| Not Vulnerable: |
SnugServer SnugServer 4.3.0.128 |
Discussion
SnugServer FTP Directory Traversal Vulnerability
SnugServer is prone to a directory-traversal vulnerability in the FTP service because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue can allow an attacker to download or upload arbitrary files outside of the FTP server root directory. This may aid in further attacks.
SnugServer 4.3.0.126 is affected; other versions may also be vulnerable.
SnugServer is prone to a directory-traversal vulnerability in the FTP service because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue can allow an attacker to download or upload arbitrary files outside of the FTP server root directory. This may aid in further attacks.
SnugServer 4.3.0.126 is affected; other versions may also be vulnerable.
Exploit / POC
SnugServer FTP Directory Traversal Vulnerability
Attackers can use readily available tools and commands to exploit this issue.
Attackers can use readily available tools and commands to exploit this issue.
Solution / Fix
SnugServer FTP Directory Traversal Vulnerability
Solution:
Reportedly the issue is fixed in version 4.3.0.128 but this has not been confirmed. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed in version 4.3.0.128 but this has not been confirmed. Please contact the vendor for more information.