|
Multiple Vendor FTP pipe Vulnerability
There is a feature implementation in a number of ftp clients shipped with unix operating systems that may be a security threat. This issue has to do with handling filenames when the user is specifying files to be retrieved from an ftp server. If the filename begins with a '|' character, the client will execute the following characters in the filename as shell commands. The command execution is the result of the client misinterpreting the user-input. An attacker may be able to exploit this if files can be placed on the server with '|' characters in the filename. The victim would then have to attempt to retrieve the files. |
|
Privacy Statement |