PT-2009-6358 · Golden Ftp Server · Golden Ftp Server

Sharpe

·

Publicado

2009-12-03

·

Atualizado

2024-01-26

·

CVE-2009-4194

CVSS v2.0

6.0

Média

VetorAV:N/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Golden FTP Server versions 4.30 through 4.50
Description The issue allows remote authenticated users to delete arbitrary files via a .. (dot dot) in the DELE command. This is a directory traversal vulnerability.
Recommendations For Golden FTP Server versions 4.30 through 4.50, consider restricting access to the DELE command until a patch is available. As a temporary workaround, avoid using the DELE command with a .. (dot dot) in the command string until the issue is resolved.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-4194

Produtos afetados

Golden Ftp Server