PT-2008-4088 · Bitkinex · Bitkinex
Tan Chew Keong
·
Published
2008-06-10
·
Updated
2017-08-08
·
CVE-2008-2635
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
BitKinex version 2.9.3
Description
The issue allows remote FTP and WebDAV servers to create or overwrite arbitrary files on the client system via directory traversal vulnerabilities. This can be achieved by including a .. (dot dot) in responses to specific commands, such as a LIST command from the BitKinex FTP client or a PROPFIND command from the BitKinex WebDAV client. This vulnerability can potentially be leveraged for code execution by writing to a Startup folder.
Recommendations
For BitKinex version 2.9.3, consider restricting access to the FTP and WebDAV clients until a patch is available, and avoid using these clients to connect to untrusted servers. As a temporary workaround, restrict write access to sensitive folders, such as Startup folders, to minimize the risk of exploitation.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bitkinex