vendor:
CoreFTP Server
by:
Kevin Randall
5.3
CVSS
MEDIUM
Directory Traversal
22
CWE
Product Name: CoreFTP Server
Affected Version From: Firmware: CoreFTP Server FTP / SFTP Server v2 - Build 674
Affected Version To: Firmware: CoreFTP Server FTP / SFTP Server v2 - Build 674
Patch Exists: YES
Related CWE: CVE-2019-9649
CPE: a:coreftp:core_ftp_server
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7
2019
CoreFTP Server FTP / SFTP Server v2 – Build 674 MDTM Directory Traversal
By utilizing a directory traversal along with the FTP MDTM command, an attacker can browse outside the root directory to determine if a file exists based on return file size along with the date the file was last modified by using a .... technique
Mitigation:
Vendor has confirmed vulnerability and implemented an updated version