PT-2008-4235 · Idm Computer Solutions · Ultraedit
Tan Chew Keong
·
Publicado
2008-06-20
·
Atualizado
2017-08-08
·
CVE-2008-2795
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
UltraEdit version 14.00b
Description
A directory traversal issue exists in the FTP and SFTP clients, allowing remote FTP servers to create or overwrite arbitrary files. This can be achieved by including a .. (dot dot) or a .. (dot dot backslash) in a response to a LIST command.
Recommendations
For UltraEdit version 14.00b, consider restricting access to the FTP and SFTP clients until a patch is available. As a temporary workaround, avoid using the LIST command with untrusted FTP servers to minimize the risk of exploitation.
Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ultraedit