SmallFTPD Directory Traversal Vulnerability
BID:7472
Info
SmallFTPD Directory Traversal Vulnerability
| Bugtraq ID: | 7472 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 30 2003 12:00AM |
| Updated: | Apr 30 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to "aT4r InsaN3" <[email protected]>. |
| Vulnerable: |
smallftpd smallftpd 1.0.2 |
| Not Vulnerable: | |
Discussion
SmallFTPD Directory Traversal Vulnerability
It has been reported that Smallftpd, version 1.02, is vulnerable to a directory traversal condition. By using directory traversal sequences, an attacker can obtain files outside of the permitted directory structure.
It has been reported that Smallftpd, version 1.02, is vulnerable to a directory traversal condition. By using directory traversal sequences, an attacker can obtain files outside of the permitted directory structure.
Exploit / POC
SmallFTPD Directory Traversal Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
SmallFTPD Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
SmallFTPD Directory Traversal Vulnerability
References:
References:
- Smallftpd Homepage (Smallftpd)
- smallftpd's version 1.0.2 Directory Transversal Vulnerability ("aT4r InsaN3"
)