PT-2009-6234 · Wing Ftp · Home Ftp Server

Published

2009-11-23

·

Updated

2024-01-26

·

CVE-2009-4053

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Home FTP Server version 1.10.1.139
Description Multiple directory traversal vulnerabilities allow remote authenticated users to create arbitrary directories via directory traversal sequences in an MKD command or create files with any contents in arbitrary directories via directory traversal sequences in a file upload request.
Recommendations For Home FTP Server version 1.10.1.139, consider restricting access to the MKD command and file upload requests to minimize the risk of exploitation. As a temporary workaround, limit the ability to create directories and upload files to authorized users only. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2009-4053

Affected Products

Home Ftp Server