vendor:
WinTFTP Pro Server
by:
Pr0T3cT10n
7.5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: WinTFTP Pro Server
Affected Version From: 3.1
Affected Version To: 3.1
Patch Exists: NO
Related CWE:
CPE: a:wintftp:wintftp_pro_server:3.1
Platforms Tested: Windows XP
2010
WinTFTP Server Pro v3.1 Remote Directory Traversal Vulnerability
WinTFTP Pro Server is vulnerable to a path traversal vulnerability, which allows an unprivileged attacker to read and write files that they do not have permissions for. The vulnerability can be exploited using the FTP commands GET and PUT.
Mitigation:
Update to a patched version of WinTFTP Pro Server to prevent this vulnerability. Restrict access to the affected server to trusted users only.