Core FTP 'LIST' Command Directory Traversal Vulnerability
2015年7月21日
危険度: 中
CVE識別番号: CVE-2008-2519
情報公開日: 7 21, 2015
概要
Core FTP is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting this issue allows an attacker to write arbitrary files to locations outside of the FTP client's current directory. This could help the attacker launch further attacks.
トレンドマイクロの対策
Apply associated Trend Micro DPI Rules.
対応方法
Trend Micro Deep Security DPI Rule Number: 1003788
Trend Micro Deep Security DPI Rule Name: 1003788 - Core FTP 'LIST' Command Directory Traversal Vulnerability
影響を受けるソフトウェア
- Core FTP
- Core FTP client 2.1 Build 1565