PT-2008-6319 · Visicom Media · Aceftp Freeware+1

Tan Chew Keong

·

Publicado

2008-11-19

·

Atualizado

2017-08-08

·

CVE-2008-5175

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions AceFTP Freeware version 3.80.3 AceFTP Pro version 3.80.3
Description A directory traversal issue in the FTP client allows remote FTP servers to create or overwrite arbitrary files by including a .. (dot dot) in a response to a LIST command.
Recommendations For AceFTP Freeware version 3.80.3, consider disabling the FTP client functionality until a patch is available. For AceFTP Pro version 3.80.3, restrict access to the FTP client to minimize the risk of exploitation.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-5175

Produtos afetados

Aceftp Freeware
Aceftp Pro