TurboFTP Server Directory Traversal Vulnerability
BID:40919
Info
TurboFTP Server Directory Traversal Vulnerability
| Bugtraq ID: | 40919 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 17 2010 12:00AM |
| Updated: | Jun 17 2010 12:00AM |
| Credit: | leinakesi[at]gmail.com |
| Vulnerable: |
TurboSoft TurboFTP Server 1.20.745 TurboSoft TurboFTP Server 1.20.739 TurboSoft TurboFTP Server 1.20.726 TurboSoft TurboFTP Server 1.0.720 TurboSoft TurboFTP Server 1.0.712 TurboSoft TurboFTP Server 1.0.709 TurboSoft TurboFTP Server 1.0.705 TurboSoft TurboFTP Server 1.0.702 TurboSoft TurboFTP Server 1.0.700 TurboSoft TurboFTP Server 1.0.694 TurboSoft TurboFTP Server 1.0.690 TurboSoft TurboFTP Server 1.0.682 |
| Not Vulnerable: | |
Discussion
TurboFTP Server Directory Traversal Vulnerability
TurboFTP Server is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue can allow an attacker to download or upload arbitrary files outside the root directory. This may aid in further attacks.
TurboFTP Server 1.20.745 is vulnerable; prior versions may also be affected.
TurboFTP Server is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue can allow an attacker to download or upload arbitrary files outside the root directory. This may aid in further attacks.
TurboFTP Server 1.20.745 is vulnerable; prior versions may also be affected.
Solution / Fix
TurboFTP Server Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].