vendor:
N/A
by:
[ByteRage]
4.3
CVSS
MEDIUM
Directory Structure Disclosure
200
CWE
Product Name: N/A
Affected Version From: EFTP v2.0.7.337, GuildFTPd v0.992
Affected Version To: EFTP v2.0.7.337, GuildFTPd v0.992
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002
FTP SIZE/MDTM Command Directory Structure Disclosure Vulnerability
A user can confirm the existence and location of files and directory structure information, by submitting a 'size' or 'mdtm' command of a file. If the command is carried out by the vulnerable service, the attacker can confirm the location of the file. Submitting a 'size' or 'mdtm' command for a file outside of the FTP root could disclose directory structure information of unpublished filesystems on the host. If the requested command is fulfilled by the vulnerable service, the attacker can confirm the relative path to the file.
Mitigation:
Ensure that the FTP server is configured to restrict access to the root directory and any other sensitive directories. Ensure that the FTP server is configured to restrict access to the root directory and any other sensitive directories.