vendor:
G6 Ftp Server
by:
SecurityFocus
7.5
CVSS
HIGH
File Disclosure
200
CWE
Product Name: G6 Ftp Server
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002
G6 Ftp Server File Disclosure Vulnerability
A user can confirm the existence and location of files and directory structure information, by submitting a 'size' or 'mdtm' command of a file. If the command is carried out by the vulnerable service, the attacker can confirm the location of the file. Submitting a 'size' or 'mdtm' command for a file outside of the FTP root could disclose directory structure information of unpublished filesystems on the host. If the requested command is fulfilled by the vulnerable service, the attacker can confirm the relative path to the file.
Mitigation:
Ensure that the FTP server is configured to not allow the 'size' or 'mdtm' commands to be used on files outside of the FTP root.