Pablo Software Solutions FTP Server File/Directory Disclosure Vulnerability
BID:5283
Info
Pablo Software Solutions FTP Server File/Directory Disclosure Vulnerability
| Bugtraq ID: | 5283 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 22 2002 12:00AM |
| Updated: | Jul 22 2002 12:00AM |
| Credit: | Discovery of this issue is credited to Arnaud Jacques. |
| Vulnerable: |
Pablo Software Solutions FTP Service 1.0 |
| Not Vulnerable: | |
Discussion
Pablo Software Solutions FTP Server File/Directory Disclosure Vulnerability
Pablo Software Solutions FTP Server is prone to directory traversal attacks. An attacker may exploit this condition to escape the FTP root directory and browse the contents of arbitrary directories and files (provided they are readable by the FTP server).
Since the software typically runs with SYSTEM privileges (or the equivalent of SYSTEM privileges on Microsoft Windows 9x), this vulnerability may expose sensitive system files to remote attackers.
Pablo Software Solutions FTP Server is prone to directory traversal attacks. An attacker may exploit this condition to escape the FTP root directory and browse the contents of arbitrary directories and files (provided they are readable by the FTP server).
Since the software typically runs with SYSTEM privileges (or the equivalent of SYSTEM privileges on Microsoft Windows 9x), this vulnerability may expose sensitive system files to remote attackers.
Exploit / POC
Pablo Software Solutions FTP Server File/Directory Disclosure Vulnerability
This issue may be exploited with a web browser.
This issue may be exploited with a web browser.
Solution / Fix
Pablo Software Solutions FTP Server File/Directory Disclosure Vulnerability
Solution:
This issue has been addressed in Pablo Software Solutions FTP Server Version 1.0 Build 010 and later. Those affected by this vulnerability are advised to upgrade.
Solution:
This issue has been addressed in Pablo Software Solutions FTP Server Version 1.0 Build 010 and later. Those affected by this vulnerability are advised to upgrade.
References
Pablo Software Solutions FTP Server File/Directory Disclosure Vulnerability
References:
References:
- FTP Service Homepage (Pablo Software Solutions)