vendor:
Home FTP Server
by:
Unknown
7.5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: Home FTP Server
Affected Version From: 1.10.2.143
Affected Version To: 1.11.1.149
Patch Exists: NO
Related CWE: Unknown
CPE: a:home_ftp_server:home_ftp_server:1.10.2.143
Platforms Tested: Windows
Unknown
Directory Traversal Vulnerability in Home FTP Server
The Home FTP Server is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input. Exploiting this issue can allow an attacker to download, upload, and delete arbitrary files outside of the FTP server's root directory. This may aid in further attacks.
Mitigation:
It is recommended to update to the latest version of Home FTP Server to mitigate this vulnerability. Additionally, input validation should be implemented to sanitize user-supplied input.