Wing FTP Server 'ssh public key' Authentication Security Bypass Vulnerability
BID:48335
Info
Wing FTP Server 'ssh public key' Authentication Security Bypass Vulnerability
| Bugtraq ID: | 48335 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 20 2011 12:00AM |
| Updated: | Jun 20 2011 12:00AM |
| Credit: | Reported by the vendor |
| Vulnerable: |
wftpserver Wing FTP Server 3.8.6 wftpserver Wing FTP Server 3.8.7 wftpserver Wing FTP Server 3.8.5 wftpserver Wing FTP Server 3.8.0 |
| Not Vulnerable: |
wftpserver Wing FTP Server 3.8.8 |
Discussion
Wing FTP Server 'ssh public key' Authentication Security Bypass Vulnerability
Wing FTP Server is prone to a security-bypass vulnerability.
Attackers can exploit this issue to bypass certain security restrictions and perform unauthorized actions.
Versions prior to Wing FTP Server 3.8.8 are affected.
Wing FTP Server is prone to a security-bypass vulnerability.
Attackers can exploit this issue to bypass certain security restrictions and perform unauthorized actions.
Versions prior to Wing FTP Server 3.8.8 are affected.
Exploit / POC
Wing FTP Server 'ssh public key' Authentication Security Bypass Vulnerability
An attacker can exploit this issue by using readily available network utilities.
An attacker can exploit this issue by using readily available network utilities.
Solution / Fix
Wing FTP Server 'ssh public key' Authentication Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Wing FTP Server 'ssh public key' Authentication Security Bypass Vulnerability
References:
References:
- Wing FTP Server Homepage (Wing FTP Server)
- Wing FTP Server Release Notes (wftpserver)