vendor:
Titan FTP Server
by:
South River Technologies
8,8
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: Titan FTP Server
Affected Version From: 10.32 Build 1816
Affected Version To: 10.32 Build 1816
Patch Exists: YES
Related CWE: CVE-2014-1841, CVE-2014-1842, CVE-2014-1843
CPE: a:south_river_technologies:titan_ftp_server
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2014
Titan FTP Server Directory Traversal Vulnerabilities
It is possible to copy the complete home folder of another user by leveraging a vulnerability on the Titan FTP Server Web Interface. This is done by using the 'Move' function, and replacing the 'src' parameter value with the '/../<folder name of another user>' value. It is also possible to obtain the complete list of existing users by writing '/../' on the search bar and hitting the 'Go' button. Additionally, it is possible to observe the 'Properties' for an existing user home folder, which also allows for enumeration of existing users on the system. This is done by using the 'Properties' function, and replacing the 'src' parameter value with the '/../<folder name of another user>' value.
Mitigation:
Update to the latest version of Titan FTP Server software (Version 10.32 Build 1816)