Broker FTP server 5.9.5 for Windows NT and 9x allows a remote attacker to retrieve privileged web server system information by (1) issuing a CD command (CD C:) followed by the LS command, (2) specifying arbitrary paths in the UNC format (computernamesharename).
Name | Vendor | Start Version | End Version |
---|---|---|---|
Broker_ftp_server | Transsoft | * | 5.9.5.0 (including) |
Broker_ftp_server | Transsoft | 4.0 (including) | 4.0 (including) |
Broker_ftp_server | Transsoft | 4.7.5.0 (including) | 4.7.5.0 (including) |
Broker_ftp_server | Transsoft | 5.0 (including) | 5.0 (including) |
Broker_ftp_server | Transsoft | 5.1 (including) | 5.1 (including) |