|
|
Info |
Last Modified |
| 10 months ago |
|
|
|
|
Description |
ArGoSoft FTP Server has a flaw that allows a remote attacker to access arbitrary files and directories outside of the FTP base path. The issue is due the server not properly checking permissions of .lnk files that are linked to arbitrary paths. By uploading a specially crafted .lnk file, an attacker can traverse out of the FTP base path to any directory.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Confidentiality,
Loss of Integrity
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
|
|
Solution |
Upgrade to version 1.4.1.4 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.
|
|
Products |
|
FTP Server
 |
1.2.2.2 |
|
|
|
|
|
Credit |
- ByteRage - byterage
yahoo.com - Personal Page
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|