RhinoSoft Serv-U FTP Server Directory Traversal Vulnerability
BID:50875
Info
RhinoSoft Serv-U FTP Server Directory Traversal Vulnerability
| Bugtraq ID: | 50875 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 30 2011 12:00AM |
| Updated: | Nov 30 2011 12:00AM |
| Credit: | Kingcope |
| Vulnerable: |
Rhino Software Serv-U 9.0 .5 Rhino Software Serv-U 7.4 0 Rhino Software Serv-U 9.4.0.0 Rhino Software Serv-U 9.3.0.1 Rhino Software Serv-U 9.2.0.1 Rhino Software Serv-U 9.1.0.4 Rhino Software Serv-U 9.1.0.2 Rhino Software Serv-U 9.1.0.0 Rhino Software Serv-U 9.0.0.1 Rhino Software Serv-U 8.3.0.23 Rhino Software Serv-U 8.3.0.2 Rhino Software Serv-U 8.3.0.1 Rhino Software Serv-U 8.3.0.0 Rhino Software Serv-U 8.2.0.3 Rhino Software Serv-U 8.2.0.0 Rhino Software Serv-U 8.1.0.0 Rhino Software Serv-U 8.0.0.0 Rhino Software Serv-U 7.9.0.0 Rhino Software Serv-U 7.8.0.0 Rhino Software Serv-U 7.7.0.0 Rhino Software Serv-U 7.6.0.0 Rhino Software Serv-U 7.5.0.0 Rhino Software Serv-U 7.4.0.1 Rhino Software Serv-U 7.4.0.0 Rhino Software Serv-U 7.3.0.2 Rhino Software Serv-U 7.3.0.0 Rhino Software Serv-U 7.2.0.1 Rhino Software Serv-U 7.2.0.0 Rhino Software Serv-U 7.0.0.1 Rhino Software Serv-U 10.5 Rhino Software Serv-U 10.3.0.1 Rhino Software Serv-U 10.3.0.0 Rhino Software Serv-U 10.2.0.2 Rhino Software Serv-U 10.2.0.0 Rhino Software Serv-U 10.1.0.1 |
| Not Vulnerable: | |
Discussion
RhinoSoft Serv-U FTP Server Directory Traversal Vulnerability
RhinoSoft Serv-U FTP Server is prone to a directory-traversal vulnerability because the application fails to sufficiently sanitize user-supplied input.
Exploiting this issue allows an authenticated user to download, upload, or list files outside the FTP root directory, which may lead to other attacks.
Serv-U FTP Server 10.5 and prior are vulnerable.
RhinoSoft Serv-U FTP Server is prone to a directory-traversal vulnerability because the application fails to sufficiently sanitize user-supplied input.
Exploiting this issue allows an authenticated user to download, upload, or list files outside the FTP root directory, which may lead to other attacks.
Serv-U FTP Server 10.5 and prior are vulnerable.
Exploit / POC
RhinoSoft Serv-U FTP Server Directory Traversal Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
RhinoSoft Serv-U FTP Server Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
RhinoSoft Serv-U FTP Server Directory Traversal Vulnerability
References:
References:
- Serv-U Homepage (RhinoSoft)