J-Security Center

Title: TransSoft Broker FTP Server Directory Traversal Vulnerability

Severity: HIGH

Description:

Broker is a Windows FTP server from TransSoft.

Versions of Broker are vulnerable to directory traversals.

Broker fails to restrict a remote user's navigation of the host filesystem. By submitting a CD command argumented with a valid MS DOS drive letter (ie CD C:) a user can use an FTP client to inspect the contents of arbitrary directories on the server. Floppy drives (A:) and CD ROM volumes are similarly accessible. An LS command will list the contents of any directory reached in this way.

This bug also permits the remote user to specify arbitrary paths in UNC format, ie \\computername\sharename, where computername = the NetBIOS name of the computer, and sharename = the share name of the folder.


An attacker could use this knowledge of the host's filesystem to exploit other possible vulnerabilities and further compromise the target system.

Affected Products:

  • TransSoft Broker FTP Server 4.0.0
  • TransSoft Broker FTP Server 4.7.0 .5.0
  • TransSoft Broker FTP Server 5.0.0
  • TransSoft Broker FTP Server 5.1.0
  • TransSoft Broker FTP Server 5.7.0
  • TransSoft Broker FTP Server 5.9.5 .0

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.