J-Security Center

Title: XLight FTP Server Unspecified Remote Directory Traversal Vulnerability

Severity: MODERATE

Description:

XLight FTP Server is a commercially available FTP server. It is available for the Microsoft Windows platform.

A problem has been identified in the XLight FTP Server when handling certain characters on the commandline. Because of this, an attacker could potentially gain access to sensitive information on vulnerable hosts.

Specific details concerning this issue are not available. What is known is that it is possible for attackers to gain access to files outside of the FTP root directory. An attacker taking advantage of this issue could gain access to files with the same permissions granted to the FTP server software.

This Bugtraq ID will be further updated when additional information is available.

Affected Products:

  • XLight FTP Server XLight FTP Server 1.25.0

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.