Core FTP 'XCRC' Command Directory Traversal Vulnerability
BID:65430
Info
Core FTP 'XCRC' Command Directory Traversal Vulnerability
| Bugtraq ID: | 65430 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-1442 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 05 2014 12:00AM |
| Updated: | Feb 05 2014 12:00AM |
| Credit: | Luciano Martins, Fara Rustein. |
| Vulnerable: |
Coreftp Core FTP 1.2.build 511 |
| Not Vulnerable: |
Coreftp Core FTP 1.2.Build 515 |
Discussion
Core FTP 'XCRC' Command Directory Traversal Vulnerability
Core FTP is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
A remote attacker could exploit the vulnerability using directory-traversal characters ('../') to access arbitrary files that contain sensitive information. Information harvested may aid in launching further attacks.
Core FTP 1.2 build 511 is vulnerable; other versions may also be affected.
Core FTP is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
A remote attacker could exploit the vulnerability using directory-traversal characters ('../') to access arbitrary files that contain sensitive information. Information harvested may aid in launching further attacks.
Core FTP 1.2 build 511 is vulnerable; other versions may also be affected.
Exploit / POC
Core FTP 'XCRC' Command Directory Traversal Vulnerability
An attacker can use readily available tools to exploit this issue.
An attacker can use readily available tools to exploit this issue.
Solution / Fix
Core FTP 'XCRC' Command Directory Traversal Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.