vendor:
FtpDisc
by:
R3d@l3rt, Sp@2K, Sunlight
7.5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: FtpDisc
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE: N/A
CPE: a:ftpdisc:ftpdisc:1.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: iPhone, iPod 3GS with 4.2.1 firmware
2011
FtpDisc v1.0 for iPhone / iPod touch, Directory Traversal
There is directory traversal vulnerability in the FtpDisc. Exploit Testing involves connecting to the FTP server using the command line and then using the 'cd' command to traverse the directory structure.
Mitigation:
Ensure that the application is not vulnerable to directory traversal attacks by validating user input and restricting access to sensitive files and directories.