WarFTPd Multiple Macro Vulnerabilities

BID:919

Info

WarFTPd Multiple Macro Vulnerabilities

Bugtraq ID: 919
Class: Input Validation Error
CVE:
Remote: Yes
Local: Yes
Published: Jan 06 2000 12:00AM
Updated: Jan 06 2000 12:00AM
Credit: Posted to Bugtraq by Sir Dystic of the cDc <[email protected]> on January 5 2000.
Vulnerable: Jgaa WarFTPd 1.70 b
Jgaa WarFTPd 1.67 b2
Not Vulnerable:

Discussion

WarFTPd Multiple Macro Vulnerabilities

WarFTPd ships with various macros to assist in the setup of complex FTP sites.

It is possible to call these macros remotely, some of which can be used to compromise the server. Some of these macros will give out server and operating system information, and can be used to reveal the contents of files in error messages, including the configuration files for WarFTP which can include plaintext administrator passwords.

The extent of the vulnerability differs between versions of WarFTPd:

Version 1.67b2 and prior:
Authenticated users can gain access to restricted files.

Version 1.70:
Remote attackers can gain access to any file on the system, as well as run any system command with administrative priveleges if an ODBC driver is installed. This can be done without needing to be logged into the FTP server.

Exploit / POC

WarFTPd Multiple Macro Vulnerabilities

execute "literal [filename]"

you will get the error:
500 'file contents' : command not understood

Solution / Fix

WarFTPd Multiple Macro Vulnerabilities

Solution:
Patches have been provided for both v1.70 and v1.67b2 or older, available at:

http://war.jgaa.com/alert/files
and
ftp://ftp.no.jgaa.com/

References

WarFTPd Multiple Macro Vulnerabilities

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report