| New User, Welcome! Login |
Xlight FTPd Multiple Directory Traversal in SFTP
| From: |
bill accensussecurity com |
| To: |
bugtraq securityfocus com |
| Cc: |
|
| Subject: |
Xlight FTPd Multiple Directory Traversal in SFTP |
| Date: |
Mon - Jul 05, 2010 04:47 PM |
Accensus Security Group Vulnerability Advisory [L-03]
Date: 7/5/2010
Vendor: http://www.xlightftpd.com/
Effected Software: Xlight FTP Server 3.5.5
Description of Vulnerability:
The SFTP server contains several directory traversal vulnerabilities: get, ls, rm, rename, etc. For example get ../../../../boot.ini will grab c:\boot.ini
Severity: Medium
Local / Remote: Local
Timeline:
Vendor informed 7/2, fix released 7/4
www.accensussecurity.com
|
|
|
Copyright © 1995-2012 LinuxRocket.net. All rights reserved.
Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!