SmartFTP Daemon 0.2 allows a local user to access arbitrary files by uploading and specifying an alternate user configuration file via a .. (dot dot) attack.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Smartftp_daemon |
Mindstorm |
0.2 (including) |
0.2 (including) |
References