Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Multiple Vendor FTP pipe Vulnerability

There is a feature implementation in a number of ftp clients shipped with unix operating systems that may be a security threat.

This issue has to do with handling filenames when the user is specifying files to be retrieved from an ftp server.

If the filename begins with a '|' character, the client will execute the following characters in the filename as shell commands.

The command execution is the result of the client misinterpreting the user-input.

An attacker may be able to exploit this if files can be placed on the server with '|' characters in the filename. The victim would then have to attempt to retrieve the files.







 

Privacy Statement
Copyright 2009, SecurityFocus