Directory Traversal Vulnerability in EFTP

A vulnerability exists in Encrypted File Transfer Protocol 2.0.8.346

Ken Pfeil

January 8, 2002

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported December 28, 2001, byErtan Kurt.

VERSION AFFECTED

  • Encrypted File Transfer Protocol 2.0.8.346 for Windows

 

DESCRIPTION
Avulnerability exists in Encrypted File Transfer Protocol 2.0.8.346 that anattacker can use to break out of his or her home directory and see the contentsof every drive and directory on the vulnerable host. Issuing the command “CWD…” and then “CWD ” changes the current directory to the root drive.However, the attacker has to following the procedure listed above he or shewants to change the working directory to list another directory’s content.

 


VENDOR RESPONSE

Thevendor, Encypted FTP, has issued release2.0.8.348, which corrects this vulnerability.

 

CREDIT
Discovered by ErtanKurt.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like