|
|
| |
| PlatinumFTPserver "simplifies management of all your FTP clients with regards to sending and receiving program and data files over an IP connection". A vulnerability in the product allows remote attackers to supply formatting strings to the FTP server. This would allow them to cause the server to execute arbitrary code. |
| |
Credit:
The information has been provided by Jan-Olivier Filiols and Philippe Oechslin.
|
| |
Vulnerable systems:
* PlatinumFTPserver version 1.0.18
A remote user can supply a specially formatted command to trigger a format string flaw in PlatinumFTPserver and potentially execute arbitrary code. Some vulnerable commands are provided:
user %s%s%s%s
mkdir %s%s%s%s
rename filename %s%s%s%s
|
|
|
|
|