CVE-2014-1843
Titan FTP Server 10.32 Build 1816 - Directory Traversal
Record summary
CVE-2014-1843 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attackers to obtain the property information of an arbitrary home folder via a Properties action with a .. (dot dot) in the src parameter.
Exploitation context
Proofs of concept
1Catalogued exploits
ExploitDBTitan FTP Server 10.32 Build 1816 - Directory TraversalExploitDB exploitby Fara RusteinNot analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMTitan FTP Server < 10.40 - User Properties TraversalCVSS 5
Titan FTP Server versions prior to 10.40 build 1829 contain a directory traversal vulnerability that allows remote attackers to view "Properties" of user folders via path traversal. This enables user enumeration and access to sensitive user information that could aid in launching further attacks.
Impact
Unauthenticated attackers can exploit directory traversal to view properties of user folders, enabling user enumeration and reconnaissance for launching targeted attacks against Titan FTP Server.
Remediation
Update Titan FTP Server to version 10.40 build 1829 or later that properly validates file paths and prevents directory traversal in user property access.
Source: ProjectDiscovery