FTP Rush Directory Traversal Vulnerability
BID:42283
Info
FTP Rush Directory Traversal Vulnerability
| Bugtraq ID: | 42283 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 05 2010 12:00AM |
| Updated: | Aug 05 2010 12:00AM |
| Credit: | High-Tech Bridge SA |
| Vulnerable: |
IoRush Software FTP Rush 1.1.3 |
| Not Vulnerable: | |
Discussion
FTP Rush Directory Traversal Vulnerability
FTP Rush is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue can allow an attacker to download or upload arbitrary files. This may aid in further attacks.
FTP Rush 1.1.3 is vulnerable; prior versions may also be affected.
FTP Rush is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue can allow an attacker to download or upload arbitrary files. This may aid in further attacks.
FTP Rush 1.1.3 is vulnerable; prior versions may also be affected.
Exploit / POC
FTP Rush Directory Traversal Vulnerability
Attackers can use readily available tools and commands to exploit this issue.
Attackers can use readily available tools and commands to exploit this issue.
Solution / Fix
FTP Rush Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
FTP Rush Directory Traversal Vulnerability
References:
References:
- FTP Rush Homepage (IoRush Software )
- Directory Traversal in FTP Rush ([email protected])