Xynph FTP Server Relative Path Directory Traversal Vulnerability
BID:6587
Info
Xynph FTP Server Relative Path Directory Traversal Vulnerability
| Bugtraq ID: | 6587 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 11 2003 12:00AM |
| Updated: | Jan 11 2003 12:00AM |
| Credit: | Vulnerbility discovery credited to "Zero-X www.lobnan.de Team" <[email protected]>. |
| Vulnerable: |
Xynph FTP Server Xynph FTP Server 1.0 |
| Not Vulnerable: | |
Discussion
Xynph FTP Server Relative Path Directory Traversal Vulnerability
A problem with the handling of input has been reported in Xynph FTP Server. Under some circumstances, it may be possible for a remote user to escape the FTP root directory using relative path notation. This could allow unauthorized access to systems using the vulnerable software.
A problem with the handling of input has been reported in Xynph FTP Server. Under some circumstances, it may be possible for a remote user to escape the FTP root directory using relative path notation. This could allow unauthorized access to systems using the vulnerable software.
Exploit / POC
Xynph FTP Server Relative Path Directory Traversal Vulnerability
This vulnerability may be exploited by issuing the following command on a vulnerable host:
cd ...
This vulnerability may be exploited by issuing the following command on a vulnerable host:
cd ...