20040704 Fastream NETFile FTP/Web Server Input validation Errorsmailing list
http://marc.info/?l=bugtraq&m=108904874104880&w=2 CVE-2004-0676
Fastream NETFile FTP/Web Server 6.5/6.7 - Directory Traversal
Record summary
CVE-2004-0676 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit.
Description
Directory traversal vulnerability in Fastream NETFile FTP/Web Server 6.7.2.1085 and earlier allows remote attackers to create or delete arbitrary files via .. (dot dot) and // (double slash) sequences in the filename parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBFastream NETFile FTP/Web Server 6.5/6.7 - Directory TraversalExploitDB exploitby Andres Tarasco AcunaNot analyzed1 file
References
5haxorcitos.com
http://www.haxorcitos.com/Fastream_advisory.txt 10658vdb entry
http://www.securityfocus.com/bid/10658 fastream-mkdir-file-upload(16613)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/16613 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-0676