CVE-2014-1842
Titan FTP Server 10.32 Build 1816 - Directory Traversal
Record summary
CVE-2014-1842 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attackers to list all usernames via a Go action with a .. (dot dot) in the search-bar value.
Exploitation context
Proofs of concept
1Catalogued exploits
ExploitDBTitan FTP Server 10.32 Build 1816 - Directory TraversalExploitDB exploitby Fara RusteinNot analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMTitan FTP Server Search Function < 10.40 - User EnumerationCVSS 5
Titan FTP Server versions prior to 10.40 build 1829 contain a directory traversal vulnerability in the web interface search functionality. Remote attackers can list all existing users by submitting "/../" in the search bar, enabling user enumeration and reconnaissance.
Impact
Unauthenticated attackers can exploit directory traversal in the web interface search functionality to enumerate all existing users, facilitating brute-force and targeted attacks against Titan FTP Server.
Remediation
Update Titan FTP Server to version 10.40 build 1829 or later that properly sanitizes search input and prevents directory traversal in the search bar.
Source: ProjectDiscovery