CompleteFTP Server Directory Traversal Vulnerability
BID:40507
Info
CompleteFTP Server Directory Traversal Vulnerability
| Bugtraq ID: | 40507 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 01 2010 12:00AM |
| Updated: | Jun 01 2010 12:00AM |
| Credit: | Sow Ching Shiong |
| Vulnerable: |
Enterprise Distributed Technologies CompleteFTP 4.0.2 |
| Not Vulnerable: |
Enterprise Distributed Technologies CompleteFTP 4.0.3 |
Discussion
CompleteFTP Server Directory Traversal Vulnerability
CompleteFTP Server is prone to a directory-traversal vulnerability in the FTP service because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue can allow an attacker to download or upload arbitrary files outside of the FTP server root directory. This may aid in further attacks.
CompleteFTP Server 4.0.2 is affected; prior versions may also be vulnerable.
CompleteFTP Server is prone to a directory-traversal vulnerability in the FTP service because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue can allow an attacker to download or upload arbitrary files outside of the FTP server root directory. This may aid in further attacks.
CompleteFTP Server 4.0.2 is affected; prior versions may also be vulnerable.
Exploit / POC
CompleteFTP Server Directory Traversal Vulnerability
Attackers can use readily available tools and commands to exploit this issue.
Attackers can use readily available tools and commands to exploit this issue.
Solution / Fix
CompleteFTP Server Directory Traversal Vulnerability
Solution:
This issue is fixed in version 4.0.3. Please contact the vendor for more information.
Solution:
This issue is fixed in version 4.0.3. Please contact the vendor for more information.
References
CompleteFTP Server Directory Traversal Vulnerability
References:
References:
- CompleteFTP - Homepage (Enterprise Distributed Technologies)
- CompleteFTP History (Enterprise Distributed Technologies)