Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

FTP:COMMAND:MULTIPLE-CMD-DIRTRA

Severity

Medium

Recommended

No

Recommended Action

Drop

Category

FTP

Keywords

FTP Server Multiple Command Directory Traversal

Release Date

2013/07/01

Update Number

2277

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

FTP: FTP Server Multiple Command Directory Traversal


This signature detects directory traversal attempts against FTP Server. Attackers can perform a directory traversal to retrieve any file that is available to logged in user.

Extended Description

RhinoSoft Serv-U FTP server is prone to a directory-traversal vulnerability because the application fails to sufficiently sanitize user-supplied input. Exploiting this issue allows an attacker to write arbitrary files to locations outside of the application's current directory. This could help the attacker launch further attacks. Serv-U FTP server 7.2.0.1 is vulnerable; other versions may also be affected.

Affected Products

  • Rhino Software Serv-U 7.2.0.1

References

  • BugTraq: 38242
  • BugTraq: 37041
  • BugTraq: 31563
  • CVE: CVE-2008-4501

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out