|
|
Info |
Last Modified |
| 6 months ago |
|
|
|
|
Description |
Golden FTP Server Pro contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered due to an input validation error in the handling of the LS command. By changing directory to a share and then passing "\.." as an argument to the LS command, it will disclose the contents of the application directory (e.g. containing files with names of valid users) resulting in a loss of confidentiality.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Information Disclosure,
Input Manipulation
Impact:
Loss of Confidentiality
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
|
|
Solution |
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.
|
|
Products |
|
Golden FTP Server
 |
2.6 |
|
|
|
|
|
|
Credit |
- Lachlan. H - pseudonym_oky
ahoo.com -
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|