|
|
|
![]() |
Vulnerability Note VU#110803CrushFTP Server does not adequately filter user input thereby permitting directory traversalOverviewCrushFTP allows access to files outside the FTP root directory through directory traversal.I. DescriptionCrushFTP is a Java-based FTP server available for Linux, Mac OS, and Windows. CrushFTP can be configured to limit access to files under a designated FTP root directory. However, CrushFTP allows an attacker to get files outside this directory through '../' directory traversal.II. ImpactCrushFTP allows an attacker to see any file in the filesystem, including potentially sensitive and critical system files.III. SolutionUpgrade to version 2.1.7 or later of CrushFTP at:http://www.crushftp.com
Referenceshttp://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2001-0583 Thanks to Joe Testa for discovering this vulnerability. This document was written by Shawn Van Ittersum.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||