glFtpD daemon sitenfo.sh directory traversal
| glftpd-sitenfosh-directory-traversal (19401) |
Description:
The glFtpD daemon could allow an authenticated remote attacker to traverse directories and obtain sensitive information, caused by a vulnerability in the sitenfo.sh script. The sitenfo.sh script is part of a suite of zip based plug-ins that is distributed with gIFtpD by default and is used to allow users to read .nfo and .diz files from within zip archives. A remote authenticated attacker could send specially-crafted parameters to the sitenfo.sh script to traverse directories and determine if a file exists on a targeted system, view directory listings outside of the FTP directory, or view files within arbitrary zip files on a victim's system.
Consequences:
Obtain Information
Remedy:
No remedy available as of July 9, 2011.
References:
- BugTraq Mailing List, Thu Feb 17 2005 - 21:21:02 CST : Multiple vulnerabilities in Glftpd v1.26 - v2.00 default zip based plug-ins.
- glFtpD Web site: The Official glFtpD Website.
- BID-12586: glFTPD ZIP Plugins Multiple Directory Traversal Vulnerabilities
- CVE-2005-0483: Multiple directory traversal vulnerabilities in sitenfo.sh, sitezipchk.sh, and siteziplist.sh in Glftpd 1.26 to 2.00 allow remote authenticated users to (1) determine the existence of arbitrary files, (2) list files in restricted directories, or (3) read arbitrary files from within ZIP or gzip files, via .. (dot dot) sequences and globbing (*) characters in a SITE NFO command.
Platforms Affected:
- FreeBSD FreeBSD
- Team glFTPd glFTPd 1.26 - 2.0
Reported:
Feb 17, 2005
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
