Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

RhinoSoft Serv-U FTP Server 'rnto' Command Directory Traversal Vulnerability

RhinoSoft Serv-U FTP server is prone to a directory-traversal vulnerability because the application fails to sufficiently sanitize user-supplied input.

Exploiting this issue allows an attacker to write arbitrary files to locations outside of the application's current directory. This could help the attacker launch further attacks.

Serv-U FTP server 7.2.0.1 is vulnerable; other versions may also be affected.







 

Privacy Statement
Copyright 2009, SecurityFocus