|
|
Info |
Last Modified |
| 2 months ago |
|
|
|
|
Description |
ArGoSoft FTP Server contains a flaw that may allow a malicious user to upload .lnk shortcut files. The issue is due to an unknown error in the product. It is possible that the flaw may allow the malicious user to use the uploaded .lnk shortcut files to access arbitrary files and directories outside of the FTP base path resulting in a loss of confidentiality or integrity.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Confidentiality,
Loss of Integrity
Exploit:
Exploit Unknown
Disclosure:
OSVDB Verified
|
|
Solution |
Upgrade to version 1.4.2.2 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.
|
|
Products |
|
ArGoSoft FTP Server
 |
1.4.2.1 |
|
|
|
|
|
|
Credit |
Unknown or Incomplete
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|