Pablo Sofware Solutions FTP server Directory Traversal Vulnerability

From: Securiteinfo.com (webmasterat_private)
Date: Mon Jul 22 2002 - 14:09:11 PDT

  • Next message: Richard Miller: "Re: SSH Protocol Trick"

    Pablo Sofware Solutions FTP server Directory Traversal Vulnerability
    
    
    .oO  Overview Oo.
    Pablo Software Solutions FTP server version 1.0 build 9 shows files and 
    directories that reside outside the normal FTP root directory. 
    Discovered on 2002, July, 20th
    Vendor: Pablo Software Solutions
    
    Pablo's FTP Server is a multi threaded FTP server for Windows 98/NT/XP. 
    It comes with an easy to use interface and can be accessed from the system 
    tray.  
    The server handles all basic FTP commands and offers easy user account 
    management and support for virtual directories.
    This FTP server can shows file and directory content that reside outside the 
    normal FTP root directory.
    
    
    .oO  Details Oo.
    The vulnerability can be done using the MS-DOS ftp client. When you are 
    logged on the server, you can send a dir \..\, or a dir \..\WINNT, supposed 
    your root directory is c:\ftp_server 
    
    
    .oO  Solution Oo.
    The vendor has been informed and has solved the problem.
    Download Pablo's FTP Server Build 10 at : 
    http://www.pablovandermeer.nl/ftp_server.html
    
    
    .oO  Discovered by Oo.
    Arnaud Jacques
    webmasterat_private
    http://www.securiteinfo.com
    



    This archive was generated by hypermail 2b30 : Tue Jul 23 2002 - 11:52:48 PDT