Directory Traversal Vulnerability in EFTP
A vulnerability exists in Encrypted File Transfer Protocol 2.0.8.346
January 8, 2002
Reported December 28, 2001, byErtan Kurt.
VERSION AFFECTED
Encrypted File Transfer Protocol 2.0.8.346 for Windows
DESCRIPTION
Avulnerability exists in Encrypted File Transfer Protocol 2.0.8.346 that anattacker can use to break out of his or her home directory and see the contentsof every drive and directory on the vulnerable host. Issuing the command “CWD…” and then “CWD ” changes the current directory to the root drive.However, the attacker has to following the procedure listed above he or shewants to change the working directory to list another directory’s content.
VENDOR RESPONSE
Thevendor, Encypted FTP, has issued release2.0.8.348, which corrects this vulnerability.
CREDIT
Discovered by ErtanKurt.
About the Author
You May Also Like