OSVDB ID: 4094

Title: EFTP LS Command Traversal Authentication Information Disclosure

Info

Disclosure

Sep 12, 2001

Discovery

Unknown

Dates

Exploit

Sep 12, 2001

Solution

Unknown

Description

EFTP contains a flaw that allows a remote attacker traverse the file system using a directory traversal style attack (../../). If such a request is made to a network share, it will force the system to send out authentication credentials to the network. Used in conjunction with a third party sniffing tool, the username/password can be obtained.

Classification

Location: Remote/Network Access Required
Attack Type: Information Disclosure, Input Manipulation
Impact: Loss of Confidentiality, Loss of Integrity
Exploit: Exploit Available
Disclosure: OSVDB Verified

Solution

Upgrade to version 3.2 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Lester Clayton Limited

EFTP

2.0.7.337

References

Credit

  • ByteRage - byterageBrand New Doo Dooyahoo.com - Personal Page


Direct URL: http://osvdb.org/36218