PT-2020-13054 · Dong Joo Cho · File Transfer Ifamily

Benjamin Kunz Mejri

·

Published

2020-04-23

·

Updated

2020-04-30

·

CVE-2020-12128

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions DONG JOO CHO File Transfer iFamily version 2.1
Description The issue allows directory traversal related to the ./etc/ path. This means an attacker could potentially access files or directories outside the intended directory structure by manipulating the path.
Recommendations For DONG JOO CHO File Transfer iFamily version 2.1, consider restricting access to sensitive directories and files to minimize the risk of exploitation until a patch is available. As a temporary workaround, limit the ability to traverse directories using the ./etc/ path.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-12128

Affected Products

File Transfer Ifamily