Cooolsoft PowerFTP Server Path Disclosure Vulnerability
BID:4072
Info
Cooolsoft PowerFTP Server Path Disclosure Vulnerability
| Bugtraq ID: | 4072 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 11 2002 12:00AM |
| Updated: | Feb 11 2002 12:00AM |
| Credit: | This issue was publicized in a Strumpf Noir Society Advisory on February 11th, 2002. |
| Vulnerable: |
Cooolsoft PowerFTP 2.24 Cooolsoft PowerFTP 2.23 Cooolsoft PowerFTP 2.10 Cooolsoft PowerFTP 2.0 3 |
| Not Vulnerable: | |
Discussion
Cooolsoft PowerFTP Server Path Disclosure Vulnerability
PowerFTP is a commercial FTP server for Microsoft Windows 9x/ME/NT/2000/XP operating systems. It is maintained by Cooolsoft.
PowerFTP discloses absolute path information when a FTP user issues a PWD command.
This information may be used to aid in further "intelligent" attacks against the host running the vulnerable FTP server.
PowerFTP is a commercial FTP server for Microsoft Windows 9x/ME/NT/2000/XP operating systems. It is maintained by Cooolsoft.
PowerFTP discloses absolute path information when a FTP user issues a PWD command.
This information may be used to aid in further "intelligent" attacks against the host running the vulnerable FTP server.
Solution / Fix
Cooolsoft PowerFTP Server Path Disclosure Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.