PlatinumFTPServer 1.0.6 - Information Disclosure

EDB-ID:

22112

CVE:

N/A




Platform:

Windows

Date:

2002-12-30


source: https://www.securityfocus.com/bid/6492/info

It has been reported that PlatinumFTPserver fails to properly sanitize some FTP commands. By sending a malicious request to the vulnerable server, using directory traversal sequences, it is possible for a remote attacker to obtain information about sensitive resources located outside of the FTP root.

Disclosure of sensitive system files may aid the attacker in launching further attacks against the target system. 

dir ..\..\..\..\