Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.11200
Category:FTP
Title:Platinum FTP Server
Summary:Platinum FTP server for Win32 has several vulnerabilities in; the way it checks the format of command strings passed to it.
Description:Summary:
Platinum FTP server for Win32 has several vulnerabilities in
the way it checks the format of command strings passed to it.

Vulnerability Insight:
The flaws leads to the following vulnerabilities in the server:

The 'dir' command can be used to examine the filesystem of the machine and
gather further information about the host by using relative directory listings
(I.E. '../../../' or '\..\..\..').

The 'delete' command can be used to delete any file on the server that the
Platinum FTP server has permissions to.

Issuing the command 'cd @/..@/..' will cause the
Platinum FTP server to crash and consume all available CPU time on
the server.

Affected Software/OS:
PlatinumFTPserver V1.0.7 is known to be affected.

Solution:
Update to the latest version of this FTP server.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

CopyrightCopyright (C) 2003 Douglas Minderhout

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.