|
|
|
![]() |
Vulnerability Note VU#413875EFTP does not adequately validate user input thereby allowing directory traversalOverviewEncrypted File Transfer Program (EFTP) does not properly validate CWD commands, allowing authenticated users to read arbitrary directories and files.I. DescriptionEncrypted File Transfer Program (EFTP) is an implementation of the FTP protocol using 448-bit Blowfish encryption. EFTP allows authenticated users to read arbitrary directories and files on the server through exploitation of a directory traversal vulnerability in the CWD command.II. ImpactAttackers with access to an EFTP account can read arbitrary directories and files on the server.III. SolutionUpgradeUpgrade to EFTP version 2.0.8 .346:
References
Thanks to Ertan Kurt for reporting this vulnerability. This document was written by Shawn Van Ittersum.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||