vendor:
Home FTP Server
by:
chr1x
7.5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: Home FTP Server
Affected Version From: vr1.10.3 (build 144)
Affected Version To: v r1.11.1 (build 149)
Patch Exists: NO
Related CWE:
CPE: Home FTP Server
Platforms Tested: Windows XP SP3
2010
Home FTP Server Directory Traversal
The Home FTP Server software allows for directory traversal, which can be exploited by an attacker to access files outside of the intended directory structure.
Mitigation:
The vendor should release a patch or update to fix the directory traversal vulnerability. In the meantime, users can mitigate the risk by restricting access to the FTP server and monitoring for any suspicious activity.