vendor:
FtpLocate
by:
newbug Tseng
7,5
CVSS
HIGH
FtpLocate <= 2.02 (current) remote exploit
78
CWE
Product Name: FtpLocate
Affected Version From: 2.02
Affected Version To: 2.02
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002
Alot of code for a cgi | vuln.
This exploit allows a remote attacker to upload a file to the vulnerable server. The exploit works by sending a GET request to the vulnerable server with a malicious payload. The payload contains a command to remove a file from the server and then echo the contents of the local file to the remote file. The exploit is written in Perl and requires the IO::Socket::INET module to be installed on the attacker's machine.
Mitigation:
Upgrade to the latest version of FtpLocate, or apply the patch provided by the vendor.