| VID |
16036 |
| Severity |
40 |
| Port |
21 |
| Protocol |
TCP |
| Class |
FTP |
| Detailed Description |
The Serv-U FTP server has a directory traversal vulnerability. FTP Serv-U is an internet FTP server from CatSoft. Authenticated users can gain access to the FTP root of the drive where Serv-U FTP has been installed. Users that have read, write, execute and list access in the home directory has the same permissions to any file which resides on the same partition as the FTP root directory. The flaw exists in the Serv-U FTP server before 2.5i allows a remote attacker to send a specially-crafted GET request containing "dot dot" sequences (/..%20) to access any files. All hidden files will be revealed even if the 'Hide hidden files' feature is on. Successful exploitation of this vulnerability could enable a remote user to gain access to systems files, password files, etc. This could lead to a complete compromise of the host.
* Platforms Affected: Cat Soft Serv-U FTP versions before 2.5i Cat Soft Serv-U FTP version 3.0 beta
* References: http://online.securityfocus.com/bid/2052 http://www.iss.net/security_center/static/5639.php |
| Recommendation |
Upgrade to the latest version of FTP Serv-U (2.5i or later), available from the Deerfield.com Web site, "Download" at http://ftpserv-u.deerfield.com/download/getftpservu.cfm |
| Related URL |
CVE-2001-0054 (CVE) |
| Related URL |
(SecurityFocus) |
| Related URL |
(ISS) |
|