vendor:
Dream FTP Server
by:
My Friend: Stack
8,8
CVSS
HIGH
Arbitrary File Disclosure
284
CWE
Product Name: Dream FTP Server
Affected Version From: Dream FTP Server 2002 - 2004
Affected Version To: Dream FTP Server 2002 - 2004
Patch Exists: NO
Related CWE: N/A
CPE: a:bolin_tech:dream_ftp_server
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2009
Dream FTP Server Arbitrary File Disclosure Vulnerability
A vulnerability in Dream FTP Server allows an attacker to disclose arbitrary files from the server. The vulnerability exists due to the lack of proper authentication and authorization checks when handling FTP requests. An attacker can exploit this vulnerability by sending a specially crafted FTP request to the server. This will allow the attacker to access arbitrary files from the server.
Mitigation:
Ensure that proper authentication and authorization checks are implemented when handling FTP requests.