Microsoft File Transfer Manager Arbitrary File Upload/Download Vulnerability
BID:5512
Info
Microsoft File Transfer Manager Arbitrary File Upload/Download Vulnerability
| Bugtraq ID: | 5512 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 19 2002 12:00AM |
| Updated: | Aug 19 2002 12:00AM |
| Credit: | Reported by "Andrew G. Tereschenko" <[email protected]>. |
| Vulnerable: |
Microsoft File Transfer Manager |
| Not Vulnerable: |
Microsoft File Transfer Manager 4.0 |
Discussion
Microsoft File Transfer Manager Arbitrary File Upload/Download Vulnerability
The Microsoft File Transfer Manager (FTM) ActiveX control is used to allow beta test customers and others to download files from certain Microsoft sites.
The File Transfer Manager is vulnerable to man in the middle attacks. An attacker may be able to upload or download any file of their choosing to or from the system running FTM.
The Microsoft File Transfer Manager (FTM) ActiveX control is used to allow beta test customers and others to download files from certain Microsoft sites.
The File Transfer Manager is vulnerable to man in the middle attacks. An attacker may be able to upload or download any file of their choosing to or from the system running FTM.
Exploit / POC
Microsoft File Transfer Manager Arbitrary File Upload/Download Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft File Transfer Manager Arbitrary File Upload/Download Vulnerability
Solution:
Reportedly, this issue has been fixed in the newest version of the File Transfer Manager which can be installed from the following website:
http://transfers.one.microsoft.com/ftm/install/HomeIE.asp
Solution:
Reportedly, this issue has been fixed in the newest version of the File Transfer Manager which can be installed from the following website:
http://transfers.one.microsoft.com/ftm/install/HomeIE.asp
References
Microsoft File Transfer Manager Arbitrary File Upload/Download Vulnerability
References:
References: