Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2008-2635 (bitkinex)

BugsAlert Home > CVE-2008-2635 (bitkinex)
 
 

Multiple directory traversal vulnerabilities in BitKinex 2.9.3 allow remote FTP and WebDAV servers to create or overwrite arbitrary files via a .. (dot dot) in (1) a response to a LIST command from the BitKinex FTP client and (2) a response to a PROPFIND command from the BitKinex WebDAV client. NOTE: this can be leveraged for code execution by writing to a Startup folder.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2635

Learn more about CVE-2008-2635 (bitkinex)
 
Tags: cve-2008-2635 bitkinex

Related Items

      CVE-2008-2169 (router, GR3000, GR4000, GR2000)

      CVE-2008-2235 (opensc)

      Vuln: ImgSvr Template Parameter Local File Include Vulnerability

      Debian update for slash

      SIPp "get_remote_video_port_media()" Buffer Overflow Vulnerability

      CVE-2007-6445 (Wireshark)

      menalto gallery: Session hijacking vulnerability

 

Pixel