vendor:
eScan Server
by:
SecurityFocus
7.5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: eScan Server
Affected Version From: 9.0.742.98
Affected Version To: 9.0.742.98
Patch Exists: YES
Related CWE: N/A
CPE: a:microworld:escan_server
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
MicroWorld eScan Server Directory Traversal Vulnerability
MicroWorld eScan Server is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data. Exploiting this issue allows an attacker to access arbitrary files outside of the FTP server root directory. This can expose sensitive information that could help the attacker launch further attacks.
Mitigation:
Input validation should be used to ensure that user-supplied data is properly sanitized.