Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:24165
HistoryJul 06, 2010 - 12:00 a.m.

Xlight FTPd Multiple Directory Traversal in SFTP

2010-07-0600:00:00
vulners.com
22

Accensus Security Group Vulnerability Advisory [L-03]
Date: 7/5/2010

Vendor: http://www.xlightftpd.com/

Effected Software: Xlight FTP Server 3.5.5

Description of Vulnerability:
The SFTP server contains several directory traversal vulnerabilities: get, ls, rm, rename, etc. For example
get …/…/…/…/boot.ini will grab c:\boot.ini

Severity: Medium

Local / Remote: Local

Timeline:
Vendor informed 7/2, fix released 7/4

www.accensussecurity.com