Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.902087
Kategorie:FTP
Titel:Titan FTP Server < 8.30.1231 Directory Traversal Vulnerabilities
Zusammenfassung:Titan FTP Server is prone to directory traversal; vulnerabilities.
Beschreibung:Summary:
Titan FTP Server is prone to directory traversal
vulnerabilities.

Vulnerability Insight:
The flaws are due to

- Input validation error when processing 'XCRC' commands, which can be exploited to determine the
existence of a file outside the FTP root directory.

- Input validation error when processing 'COMB' commands, which can be exploited to read and delete
an arbitrary file.

Vulnerability Impact:
Successful exploitation will allow attackers to download
arbitrary files and deletion of arbitrary files on the server.

Affected Software/OS:
Titan FTP Server version 8.10.1125 and prior.

Solution:
Update to version 8.30.1231 or later.

CVSS Score:
6.5

CVSS Vector:
AV:N/AC:L/Au:S/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2010-2425
BugTraq ID: 40949
http://www.securityfocus.com/bid/40949
Bugtraq: 20100617 TitanFTP Server COMB directory traversal (Google Search)
http://www.securityfocus.com/archive/1/511873/100/0/threaded
http://www.osvdb.org/65622
http://secunia.com/advisories/40237
Common Vulnerability Exposure (CVE) ID: CVE-2010-2426
Bugtraq: 20100615 TitanFTP Server Arbitrary File Disclosure (Google Search)
http://www.securityfocus.com/archive/1/511839/100/0/threaded
http://osvdb.org/65533
XForce ISS Database: tfs-xcrc-dir-traversal(59492)
https://exchange.xforce.ibmcloud.com/vulnerabilities/59492
CopyrightCopyright (C) 2010 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.