vendor:
Titan FTP Server
by:
Kevin Randall
6.5
CVSS
MEDIUM
Directory Traversal/Local File Inclusion
22
CWE
Product Name: Titan FTP Server
Affected Version From: 2019 Build 3505
Affected Version To: 2019 Build 3505
Patch Exists: YES
Related CWE: CVE-2019-10009
CPE: a:titanftp:titan_ftp_server:2019_build_3505
Platforms Tested: Windows 7 32 Bit
2019
Titan FTP Server Version 2019 Build 3505 Directory Traversal/Local File Inclusion
A Directory Traversal issue was discovered in the Web GUI in Titan FTP Server 2019 Build 3505. When an authenticated user attempts to preview an uploaded file (through PreviewHandler.ashx) by using a .... technique, arbitrary files can be loaded in the server response outside the root directory.
Mitigation:
The vulnerability has been fixed in Titan FTP Server 2019 Build 3515.