BisonFTP Information Disclosure Vulnerability
BID:6873
Info
BisonFTP Information Disclosure Vulnerability
| Bugtraq ID: | 6873 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 17 2003 12:00AM |
| Updated: | Feb 17 2003 12:00AM |
| Credit: | Discovery is credited to Jimmi Andersen. |
| Vulnerable: |
BisonFTP Bison Ftp Server V4R2 |
| Not Vulnerable: | |
Discussion
BisonFTP Information Disclosure Vulnerability
BisonFTP server can disclose information about files outside the FTP root. If an attacker submits an 'ls' command using the character sequence '@../' then the FTP server will return a directory listing for the parent directory of the FTP root.
BisonFTP server can disclose information about files outside the FTP root. If an attacker submits an 'ls' command using the character sequence '@../' then the FTP server will return a directory listing for the parent directory of the FTP root.
References
BisonFTP Information Disclosure Vulnerability
References:
References:
- [VulnDiscuss] [immune advisory] Mulitple vulnerabilities found in BisonFTP (Immune Advisory
)