Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2007-6233 (FTP Admin)

BugsAlert Home > CVE-2007-6233 (FTP Admin)
 
 

Directory traversal vulnerability in index.php in FTP Admin 0.1.0 allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the page parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-6233

Learn more about CVE-2007-6233 (FTP Admin)
 
Tags: cve-2007-6233 ftp admin

Related Items

      Brief: Adobe investigates Flash Player attacks

      TROJ_FAKEALER.GA

      CVE-2008-4829 (streamripper)

      FrSIRT - Borland StarTeam 2008 Multiple Remote Integer Overflow Vulnerabilities

      Antivirus that will rename infected files only and run in ..

      Websense "username" Cross-Site Scripting Vulnerability

      CVE-2008-5129 (poll_manager)

 

Pixel