FTP Commander Directory Traversal Vulnerability
BID:42125
Info
FTP Commander Directory Traversal Vulnerability
| Bugtraq ID: | 42125 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 02 2010 12:00AM |
| Updated: | Aug 02 2010 12:00AM |
| Credit: | High-Tech Bridge SA |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
FTP Commander Directory Traversal Vulnerability
FTP Commander is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue can allow an attacker to download or upload arbitrary files. This may aid in further attacks.
FTP Commander 8.02, 8.0 Pro, and 9.20 Deluxe are vulnerable; prior versions may also be affected.
FTP Commander is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue can allow an attacker to download or upload arbitrary files. This may aid in further attacks.
FTP Commander 8.02, 8.0 Pro, and 9.20 Deluxe are vulnerable; prior versions may also be affected.
Exploit / POC
FTP Commander Directory Traversal Vulnerability
Attackers can use readily available tools and commands to exploit this issue.
Attackers can use readily available tools and commands to exploit this issue.
Solution / Fix
FTP Commander Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
FTP Commander Directory Traversal Vulnerability
References:
References:
- Directory Traversal Vulnerability in FTP Commander (High-Tech Bridge SA)
- Directory Traversal Vulnerability in FTP Commander Deluxe (High-Tech Bridge SA)
- Directory Traversal Vulnerability in FTP Commander Pro (High-Tech Bridge SA)
- FTP Commander Homepage (InternetSoft)
- InternetSoft Homepage (InternetSoft)
- Directory Traversal Vulnerability in FTP Commander ([email protected])
- Directory Traversal Vulnerability in FTP Commander Deluxe ([email protected])
- Directory Traversal Vulnerability in FTP Commander Pro ([email protected])