Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: KunaniFTP-Server v.1.0.10 allows dictionary traversal Dec 11 2002 02:04AM
Alun Jones (alun texis com)
At 04:23 PM 12/10/2002, Zero-X www.lobnan.de Team wrote:
>Ftp> get ..\..\..\..\..\boot.ini
>200 PORT command successful
>150 Opening ASCII mode data connection for /bin/ls.

I think an FTP server that's told to "get" a file, and returns that it's
opening a connection for "/bin/ls" (i.e. making a li...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus