Xlight FTPd Multiple Directory Traversal in SFTP

看板Bugtraq作者時間15年前 (2010/07/07 02:01), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/1
Accensus Security Group Vulnerability Advisory [L-03] Date: 7/5/2010 Vendor: http://www.xlightftpd.com/ Effected Software: Xlight FTP Server 3.5.5 Description of Vulnerability: The SFTP server contains several directory traversal vulnerabilities: get, ls, rm, rename, etc. For example get ../../../../boot.ini will grab c:\boot.ini Severity: Medium Local / Remote: Local Timeline: Vendor informed 7/2, fix released 7/4 www.accensussecurity.com
文章代碼(AID): #1CCszVHA (Bugtraq)