Hyperion FTP Server Directory Traversal Vulnerability
14 Nov. 2002
Summary
Hyperion FTP Server is a powerful, reliable FTP server for Windows 95/98/NT/2000, and supports all basic FTP commands, and much more, such as passive mode. A vulnerability in the server allows remote attackers to read the content of arbitrary files.
Credit:
The information has been provided by Tamer Sahin.
Vulnerable systems:
* Hyperion FTP Server version 2.8.1
A vulnerability exists in Hyperion FTP Server that allows a remote user to traverse the directories of a target host. This may lead to the disclosure of file and directory contents. Arbitrary directories can be accessed through the use of double dot '../' techniques when using the 'ls' command.