vendor:
CoreFTP Server
by:
Kevin Randall
5.3
CVSS
MEDIUM
Directory Traversal
22
CWE
Product Name: CoreFTP Server
Affected Version From: 674
Affected Version To: 674
Patch Exists: YES
Related CWE: CVE-2019-9649
CPE: a:coreftp:core_ftp_server:2.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2019
CVE-2019-9649 CoreFTP FTP Server Version 674 and below MDTM Directory Traversal
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. Using the MDTM FTP command, a remote attacker can use a directory traversal (....) to browse outside the root directory to determine the existence of a file on the operating system, and the last mofidied date.
Mitigation:
Upgrade to CoreFTP 2.0 Build 675 or later