Home arrow Vendor Advisories arrow Open Source Vul DB arrow SeleniumServer FTP Server Multiple Command Traversal Arbitrary File Access
Friday, 21 November 2008
 
spacer.png, 0 kB
spacer.png, 0 kB
spacer.png, 0 kB
SeleniumServer FTP Server Multiple Command Traversal Arbitrary File Access
Wednesday, 15 November 2006
SeleniumServer contains a flaw that allows a remote attacker to list and download files outside of the web path. The issue is due to the FTP Server properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the 'DIR'(LIST or NLST), 'GET'(RETR), and 'PUT'(STOR) variables.
Read more...
 
spacer.png, 0 kB
     

© 2008 Intellect Information Technology Pty Ltd, Melbourne, Australia.

This page was loaded in 0.052 seconds.