New User, Welcome!     Login

Xlight FTPd Multiple Directory Traversal in SFTP

From: bill accensussecurity com
To: bugtraq securityfocus com
Cc:
Subject: Xlight FTPd Multiple Directory Traversal in SFTP
Date: Mon - Jul 05, 2010 04:47 PM


Accensus Security Group Vulnerability Advisory [L-03]
Date: 7/5/2010

Vendor: http://www.xlightftpd.com/

Effected Software: Xlight FTP Server 3.5.5

Description of Vulnerability:
The SFTP server contains several directory traversal vulnerabilities: get, ls, rm, rename, etc. For example get ../../../../boot.ini will grab c:\boot.ini

Severity: Medium

Local / Remote:  Local

Timeline:
Vendor informed 7/2, fix released 7/4

www.accensussecurity.com




Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!