OSVDB ID: 12103

Title: Fastream FTP++ Server Malformed ls Command Arbitrary Directory Listing

Info

Disclosure

Jan 19, 2001

Discovery

Unknown

Dates

Exploit

Jan 19, 2001

Solution

Unknown

Description

Fastream FTP++ Server contains a flaw that may lead to unauthorized file access. The issue is triggered when a remote attacker uses "ls" command and includes the drive letter in the requested path name, which will allow a remote attacker to list directories outside of the Faststream FTP++ Server directory, resulting in a loss of confidentiality.

Classification

Location: Remote/Network Access Required
Attack Type: Race Condition
Impact: Loss of Confidentiality
Exploit: Exploit Available
Disclosure: OSVDB Verified

Solution

Upgrade to version 2.0 Beta 10 Build 3 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Fastream Technologies

Fastream FTP++ Server

2.0

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/36218