Core FTP Server Directory Traversal and Denial of Service Vulnerabilities
BID:40609
Info
Core FTP Server Directory Traversal and Denial of Service Vulnerabilities
| Bugtraq ID: | 40609 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 07 2010 12:00AM |
| Updated: | Jun 07 2010 12:00AM |
| Credit: | leinakesi[at]gmail.com |
| Vulnerable: |
Core FTP Mini SFTP Server 1.19 Core FTP Core FTP Server 1.0.347 |
| Not Vulnerable: | |
Discussion
Core FTP Server Directory Traversal and Denial of Service Vulnerabilities
Core FTP Server is prone to a directory-traversal vulnerability and multiple denial-of-service vulnerabilities.
Exploiting these issues will allow attackers to obtain sensitive information or crash the affected application, denying further service to legitimate users.
Core FTP Server 1.0.347 and Core FTP Mini SFTP Server 1.0.347 are vulnerable; other versions may also be affected.
Core FTP Server is prone to a directory-traversal vulnerability and multiple denial-of-service vulnerabilities.
Exploiting these issues will allow attackers to obtain sensitive information or crash the affected application, denying further service to legitimate users.
Core FTP Server 1.0.347 and Core FTP Mini SFTP Server 1.0.347 are vulnerable; other versions may also be affected.
Exploit / POC
Core FTP Server Directory Traversal and Denial of Service Vulnerabilities
The following exploit code is available:
The following exploit code is available:
Solution / Fix
Core FTP Server Directory Traversal and Denial of Service Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Core FTP Server Directory Traversal and Denial of Service Vulnerabilities
References:
References: