vendor:
FTP Serv-U
by:
Jonathan Salwan
7.5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: FTP Serv-U
Affected Version From: v7.4.0.1
Affected Version To: v7.4.0.1
Patch Exists: YES
Related CWE: N/A
CPE: a:serv-u:ftp_serv-u:7.4.0.1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
FTP Serv-U v7.4.0.1 Directory Traversal Vulnerability
A vulnerability is caused due to an input validation error when handling FTP "MKD" requests. This can be exploited to escape the FTP root and create arbitrary directory on the system via directory traversal attacks using the ".." character sequence.
Mitigation:
Input validation should be done to prevent directory traversal attacks.