XLight FTP Server Unspecified Remote Directory Traversal Vulnerability
BID:9219
Info
XLight FTP Server Unspecified Remote Directory Traversal Vulnerability
| Bugtraq ID: | 9219 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 15 2003 12:00AM |
| Updated: | Dec 15 2003 12:00AM |
| Credit: | Discovery credited to Ziv Kamir. |
| Vulnerable: |
XLight FTP Server XLight FTP Server 1.25 |
| Not Vulnerable: |
XLight FTP Server XLight FTP Server 1.41 |
Discussion
XLight FTP Server Unspecified Remote Directory Traversal Vulnerability
A problem has been identified in the XLight FTP Server when handling certain characters on the commandline. Because of this, an attacker could potentially gain access to sensitive information on vulnerable hosts.
A problem has been identified in the XLight FTP Server when handling certain characters on the commandline. Because of this, an attacker could potentially gain access to sensitive information on vulnerable hosts.
Exploit / POC
XLight FTP Server Unspecified Remote Directory Traversal Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
XLight FTP Server Unspecified Remote Directory Traversal Vulnerability
Solution:
This issue has reportedly been resolved in version 1.41 of the software. This information has not been confirmed by the software vendor or Symantec.
-----
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
This issue has reportedly been resolved in version 1.41 of the software. This information has not been confirmed by the software vendor or Symantec.
-----
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
XLight FTP Server Unspecified Remote Directory Traversal Vulnerability
References:
References:
- Product Homepage (XLight FTP Server)
- Release notes for Xlight ftp server 1.41 (XLight FTP Server)