PT-2008-4328 · Acebit · Acebit Wise-Ftp
Tan Chew Keong
·
Published
2008-06-27
·
Updated
2011-03-08
·
CVE-2008-2889
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
AceBIT WISE-FTP versions 4.1.0 through 5.5.8
Description
A directory traversal issue exists in the FTP client, allowing remote FTP servers to create or overwrite arbitrary files. This can be achieved by including a .. (dot dot backslash) in a response to a LIST command.
Recommendations
For AceBIT WISE-FTP versions 4.1.0 through 5.5.8, consider disabling the FTP client functionality until a patch is available to prevent potential exploitation. Restrict access to sensitive files and directories to minimize the risk of arbitrary file creation or overwrite.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Acebit Wise-Ftp