vendor:
ColoradoFTP
by:
Rv3Laboratory [Research Team]
7.5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: ColoradoFTP
Affected Version From: ColoradoFTP v1.3 Prime Edition (Build 8)
Affected Version To: ColoradoFTP v1.3 Prime Edition (Build 8)
Patch Exists: NO
Related CWE:
CPE: cftp.coldcore.com
Platforms Tested:
Directory Traversal Vulnerability in ColoradoFTP v1.3 Prime Edition (Build 8)
The default installation and configuration of Colorado FTP Prime Edition (Build 8) is prone to a security vulnerability. Colorado FTP contains a flaw that may allow a remote attacker to traverse directories on the FTP server. A remote attacker (a colorado FTP user) can send a command (MKDIR, PUT, GET or DEL) followed by sequences (\..) to traverse directories and create, upload, download or delete the contents of arbitrary files and directories on the FTP server. To exploit the vulnerability It is important to use "\" at the beginning of string.
Mitigation:
Unknown