Search:     Advanced search
server monitoring

Broker FTP Multiple Command Arbitrary File/Directory Manipulation

Article ID: 10556
Last updated: 27 Jan, 2009
Views: 394
Posted: 22 Jan, 2009
by: Tech Pubs S.
Updated: 27 Jan, 2009
by: Tech Pubs S.

Broker FTP Multiple Command Arbitrary File/Directory Manipulation

This script is Copyright (C) 2000-2008 Tenable Network Security, Inc.

FamilyFTP
Plugin ID10556
Bugtraq ID301
CVE IDCVE-2001-0450

Description:

Some versions of Broker FTP (www.ftp-broker.com) allow
any anonymous user to browse the entire remote disk
by issuing a command like :

LIST C:


Solution : upgrade to the latest version
Risk factor : High
This article was:   Helpful | Not Helpful
Prev   Next
PlanetFileServer Remote Buffer Overflow Vulnerability     BSD ftpd Single Byte Buffer Overflow