|
Accensus Security Advisory L-02 TitanFtp Server Arbitrary File Disclosure=0D
=0D
Details=0D
=0D
==============0D
=0D
Product: TitanFTP Server=0D
=0D
Security-Risk: high=0D
=0D
Remote-Exploit: maybe, assuming anonymous ftp access=0D
=0D
Local-Exploit: yes=0D
=0D
Vendor URL: http://www.southrivertech.com/=0D
=0D
Found By: Bill Finlayson=0D
=0D
http://www.accensussecurity.com=0D
=0D
Affected: Versions 8.10.1125 and likely previous=0D
=0D
Issue: the xcrc command is susceptible to a directory traversal attack which will allow disclosure of the contents of any file on the server=0D
=0D
Details: xcrc ..//..//..//..//a.txt 1