vendor:
GuildFTPd FTP Server
by:
Jonathan Salwan
5.5
CVSS
MEDIUM
Input Validation Error
22
CWE
Product Name: GuildFTPd FTP Server
Affected Version From: 0.x.x
Affected Version To: 0.x.x
Patch Exists: NO
Related CWE:
CPE: a:guildftpd:guildftpd:0.x.x
Platforms Tested:
2009
GuildFTPd FTP Server Version 0.x.x Remote Delete Files
A vulnerability is caused due to an input validation error when handling FTP "DELE" requests. This can be exploited to escape the FTP root and delete arbitrary files on the system via directory traversal attacks using the ".." character sequence.
Mitigation:
Apply the latest patch or upgrade to a newer version of the GuildFTPd FTP Server software.