[<prev] [next>] [day] [month] [year] [list]
Message-ID: <20100705235147.26874.qmail@securityfocus.com>
Date: 5 Jul 2010 23:51:47 -0000
From: bill@...ensussecurity.com
To: bugtraq@...urityfocus.com
Subject: Xlight FTPd Multiple Directory Traversal in SFTP
Accensus Security Group Vulnerability Advisory [L-03]
Date: 7/5/2010
Vendor: http://www.xlightftpd.com/
Effected Software: Xlight FTP Server 3.5.5
Description of Vulnerability:
The SFTP server contains several directory traversal vulnerabilities: get, ls, rm, rename, etc. For example get ../../../../boot.ini will grab c:\boot.ini
Severity: Medium
Local / Remote: Local
Timeline:
Vendor informed 7/2, fix released 7/4
www.accensussecurity.com
Powered by blists - more mailing lists