|
|
| Livres Blancs : | | |
Le Cahier de Sécurité Business Orange Services présente les solutions existantes pour sécuriser une solution de ToIP
| | |
|
|
| Mini-Tagwall | | | |
Revue de presse : security, microsoft, vulnérabilité, windows, vulnerability, network, attack, google, hacker, exploit, inject, internet, remote
+ de mots clés pour la revue de presse
Annuaires des videos : virus, spyware, vmware, firmware, security, malware, lockpicking, biometric, kernel, iphone, windows, adware, password
+ de mots clés pour les videos
Revue Twitter : security, cisco, linux, defcon, firewall, vmware, metasploit, attack, server, phish, network, twitter, windows
+ de mots clés pour la revue Twitter
| | |
|
|
Exostats/Exoscan |
Nombre de tests inclus
|
29046
|
|
Tests ajoutés |
Aujourd'hui |
Ce
mois |
17 |
36 |
|
|
ID |
10565 |
Nom |
Serv-U CD Command Encoded Traversal Arbitrary File/Directory Access |
Auteurs |
This script is Copyright (C) 2000-2009 Tenable Network Security, Inc. |
Catégorie |
FTP |
Action |
infos |
Résumé |
Traverses the remote ftp root |
Description |
Synopsis :
The remote FTP server is affected by a directory traversal
vulnerability.
Description :
The remote host is running Serv-U FTP server. The installed version
fails to properly sanitize user supplied input to the 'cd' command. An
attacker could exploit this flaw to access arbitrary files on the
remote host.
See also :
http://archives.neohapsis.com/archives/bugtraq/2000-12/0043.html
Solution :
Upgrade to Serv-U 2.5i or later.
Risk factor :
Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
|
Cliquer pour le detail - Liste des tests :
Serv-U CD Command Encoded Traversal Arbitrary File/Directory Access
Dragon FTP USER Command Remote Overflow
FTP Supports Clear Text Authentication
SlimFTPd Username/Password Overflow Remote DoS
QNX RTP FTP stat Command strtok() Function Overflow
ArGoSoft FTP Server .lnk Shortcut Upload Arbitrary File Manipulation
Crob FTP Server user Field Remote Format String
Serv-U 7.x < 7.2.0.1 SFTP Directory Creation Logging DoS
Golden FTP Server <= 2.60 Information Disclosure Vulnerabilities
PlatinumFTPServer username Multiple Connection Handling Remote Format String
ProFTPD mkdir Buffer Overflow
ProFTPD on Debian Linux postinst Installation Privilege Escalation
ProFTPD src/support.c sreplace Function Remote Overflow
WU-FTPD SITE NEWER Command Memory Exhaustion DoS
ProFTPD Login Timing Account Name Enumeration
WS_FTP Multiple Command Long Argument Overflow
TYPSoft FTP Server Crafted RETR Command Sequence Remote DoS
Serv-U MDTM Command Overflow
WarFTPd USER/PASS Command Remote Overflow
ProFTPd File Transfer Newline Character Overflow
WU-FTPD wu_fnmatch() Function File Globbing Remote DoS
WS_FTP Server SITE CPWD Command Remote Overflow
Serv-U < 2.5e Multiple Vulnerabilities (OF, Path Disc)
DataWizard FTPXQ Default Accounts
oftpd PORT Command Remote DoS
3Com 3CServer/3CDaemon FTP Server Multiple Vulnerabilities (OF, FS, PD, DoS)
PFTP Default Unpassworded Account
WU-FTPD restricted-gid Directory Access Restriction Bypass
FTPd CWD Command Account Enumeration
WU-FTPD Debug Mode Client Hostname Remote Format String
Ariel FTP Server Default document Account
Sami FTP Server Multiple DoS
SunFTP Multiple Command Traversal Arbitrary File Creation/Deletion
WU-FTPD Multiple Vulnerabilities (OF, Priv Esc)
Guild FTPd Traversal Arbitrary File Enumeration
Serv-U 7.x < 7.4.0.0 Multiple Command Remote DoS
4D WebStar Pre-authentication FTP Overflow
Microsoft IIS FTP Server NLST Command Overflow DoS
smallftpd 1.0.3 Crafted Traversal Sequence Remote DoS
Anonymous FTP Writeable root Directory
glFTPd Multiple Script ZIP File Handling Arbitrary File / Directory Access
Serv-U 7.x < 7.3.0.1 Multiple Remote Vulnerabilities (DoS, Traversal)
GuildFTPd Long SITE Command Overflow
Serv-U < 8.0.0.1 Multiple Vulnerabilities (DoS, Traversal)
GlobalSCAPE Secure FTP Server (gsftps) Custom Command Long Parameter DoS
BSD ftpd Single Byte Buffer Overflow
WU-FTPD rnfr File Overwrite
Broker FTP Multiple Command Arbitrary File/Directory Manipulation
Xlight FTP Server Authentication SQL Injection Vulnerability
Serv-U CWD Command Overflow
RobotFTP Pre-authentication Command Execution DoS
3Com NBX ftpd CEL Command Remote Overflow (2)
FTP Serv-U 4.x-5.x STOU Command MS-DOS Argument Remote DoS
Windows NT FTP guest Account Present
FTP Server root Directory .rhosts File Present
WU-FTPD Unspecified Security Issue
WU-FTPD fileutils/coreutils ls -w Argument Memory Consumption DoS
XAMPP Default FTP Account
WFTP 3.21 Multiple Vulnerabilities (OF, DoS)
ProFTPD NLST Command Argument Handling Remote Overflow
FTP Privileged Port Bounce Scan
bftpd Multiple Command Remote Overflow
NETFile FTP/Web Server FTP Bounce Attack
Farmers WIFE FTP Server Multiple Command Traversal Arbitrary File Creation
ProFTPD STAT Command Remote DoS
Xlight FTP Server Multiple Remote Overflows
Sambar FTP Server Malformed SIZE Command DoS
WFTPD APPE Command Buffer Overflow
eScan Server Management Console (eserv.exe) FTP Server Arbitrary File Download
FTP Server Bad Command Sequence Accepted (Possible Backdoor/Proxy)
WU-FTPD site_exec() Function Remote Format String
Serv-U 2.5e Null Byte Saturation DoS
FTP Server root Directory .forward File Present
WU-FTPD MAIL_ADMIN Function Remote Overflow
FTP Server Any Command Accepted (Possible Backdoor/Proxy)
Microsoft IIS FTP Status Request DoS
WFTP Unpassworded Guest Account
Hummingbird Connectivity FTP Service XCWD Command Overflow
Ability FTP Server Multiple Command Remote Buffer Overflows
WU-FTPD ABOR Command Arbitrary File Access
BSD Based FTP Server Multiple glob Function Remote Overflow
WU-FTPD S/KEY Authentication ftpd.c skey_challenge Function Remote Overflow
WS_FTP Server Multiple Command Remote Overflow DoS
Crob FTP Server Multiple Vulnerabilities (OF, DoS)
WU-FTPD fb_realpath() Function Off-by-one Overflow
TYPSoft FTP Server LIST Command Traversal Arbitrary Directory Listing
HP-UX FTP Daemon PASS Command Remote Format String
Multiple Vendor Embedded FTP Service Any Username Authentication Bypass
EFTP .lnk File Handling Remote Overflow
Titan FTP Server Multiple Command Remote Overflow
WarFTPd CWD Command Remote DoS
ProFTPD 1.2.0pre4 mkdir Command Directory Name Handling Remote Overflow
WFTPD 2.41 rc11 Unauthenticated MLST Command Remote DoS
freeFTPd Multiple Command Malformed Argument Remote DoS
WS_FTP Pro Client ASCII Mode Directory Listing Handling Overflow
ArGoSoft FTP Server USER Command Account Enumeration
WU-FTPD SITE EXEC Arbitrary Local Command Execution
ProFTPD < 1.3.0rc2 Multiple Remote Format Strings
NetComm NB1300 Router FTP Default Admin Account
Multiple FTP CWD ~root Command Privilege Escalation
WS_FTP Server Multiple Vulnerabilities (Bounce, PASV Hijacking)
WS_FTP Pro Client Weak Password Encrypted
Zaurus PDA FTP Server Unpassworded root Account
Vermillion FTPD Long CWD Commands DoS
WU-FTPD QUOTE PASV Forced Core Dump Information Disclosure
Novell Netware FTPServ Malformed Input Remote DoS
Hummingbird InetD FTP Component (ftpdw.exe) Command Overflow
FTP Server No Command Accepted (Possible Backdoor/Proxy)
Solaris FTP Daemon CWD Command Account Enumeration
Serv-U SITE CHMOD Command Multiple Vulnerabilities
EFTP Newline String Handling Remote DoS
PlatinumFTPServer Multiple Vulnerabilities
PlanetFileServer mshftp.dll Data Processing Remote Overflow
Golden FTP Server Pro GET Traversal Arbitrary File Access
smallftpd Multiple Vulnerabilities (Traversal, DoS)
ProFTPD Multiple Remote Overflows (palmetto)
Crob FTP Server Connection Saturation Remote DoS
HP-UX FTPD REST Command Remote Arbitrary Memory Disclosure
TYPSoft FTP Server Malformed STOR / RETR Command DoS
FTP Server Traversal Arbitrary File Access
RaidenFTPD Multiple Command Traversal Arbitrary File Access
Windows FTP Server NULL Administrator Password
Multiple FTPD glob Command Arbitrary Command Execution
Multiple FTP Server Command Handling Overflow
Multiple FTP Server setproctitle Function Arbitrary Command Execution
SlimFTPd Multiple Command Handling Overflow
TYPSoft FTP Server Empty Username DoS
WFTPD Out of Sequence RNTO Command Remote DoS
EFTP Multiple Command Traversal Arbitrary Directory Listing
WarFTPd CWD/MKD Command Overflow
FTP Writeable Directories
Multiple FTP Server QUOTE CWD Command Home Path Disclosure
Multiple Vendor FTP Multiple PASV Command Port Exhaustion DoS
PostgreSQL Authentication Module (mod_sql) for ProFTPD USER Name Variable SQL Injection
3Com NBX ftpd CEL Command Remote Overflow (1)
Inframail FTP Server NLST Command Remote Overflow
SurgeFTP LEAK Command Remote DoS
BlackJumboDog FTP Server Multiple Command Overflow
Multiple FTP Server quote stat Command Traversal Arbitrary Directory Access
bftpd NLST Command Output Format String
Multiple Vendor FTPD on Windows Floppy Request CPU Consumption DoS
TYPSoft FTP Server Crafted RETR Command DoS
ProFTPD Command Truncation Cross-Site Request Forgery
TYPSoft FTP Server 1.10 Invalid Path Request DoS
NGC Active FTPServer 2002 Multiple Command Remote DoS
ProFTPD Auth API Multiple Auth Module Authentication Bypass
Home FTP Server Multiple Vulnerabilities
FTPshell Server 3.38 Malformed PORT/QUIT DoS
RaidenFTPD urlget Command Traversal Arbitrary File Access
ArGoSoft FTP Server < 1.4.2.8 Multiple .LNK File Handling Vulnerabilities
GoodTech FTP Server Connection Saturation DoS
Blac'oon FTP Login Error Message User Enumeration
WebWeaver FTP Aborted RETR Command Remote DoS
Titan FTP Server quote stat Command Traversal Arbitrary Directory Listing
ProFTPD 1.2.0rc2 Malformed cwd Command Format String
SunFTP GET Request Remote Overflow
DreamFTP Server username Remote Format String
WarFTPd dir Command Traversal Arbitrary Directory Listing
WS_FTP Server Path Parsing Remote DoS
Windows 98 FTP MS/DOS Device Name Request DoS
HP-UX ftpd PAM Authentication Configuration Weakness Authentication Bypass
EFTP Nonexistent File Request Installation Directory Disclosure
WS_FTP Server Multiple Vulnerabilities (OF, DoS, Cmd Exec)
HP-UX ftpd glob() Expansion STAT Buffer Overflow
ArGoSoft FTP Server XCWD Remote Overflow
Anonymous FTP Enabled
Multiple FTP Server Traversal Arbitrary File/Directory Access
WS_FTP Server CWD Command Remote DoS
ArGoSoft FTP Server DELE Command Remote Buffer Overrun
AIX FTPd libc Library Remote Buffer Overflow
WS_FTP Server STAT Command Remote Overflow
FileZilla FTP Server Multiple DoS
Titan FTP Server SITE WHO Command Resource Consumption DoS
ST FTP Service Arbitrary File/Directory Access
|
|
Cliquer pour le detail - liste des categories : |
| Mini-Tagwall des articles publiés sur SecuObs : | | | | sécurité, windows, exploit, microsoft, réseau, attaque, vulnérabilité, système, audit, outil, virus, internet, données, linux, présentation, bluetooth, vista, metasploit, protocol, shell, scanner, réseaux, trames, téléphone, paquet, wishmaster, rootkit, engineering, sysun, https, black, mobile, noyau, téléphones, conférence, mémoire, source, scapy, google, reverse, détection, malveillant, snort, sécurise, patch |
| Mini-Tagwall de l'annuaire video : | | | | virus, spyware, vmware, firmware, security, malware, lockpicking, biometric, kernel, iphone, windows, adware, password, wimax, botnet, tutorial, phish, linux, symantec, rootkit, knoppix, metasploit, network, attack, server, virtual, internet, jailbreak, notacon, conference, exploit, google, wireshark, defcon, hacker, backtrack, openbsd, intel, ettercap, firewall, source, samsung, reprap, wireless, norton |
| Mini-Tagwall des articles de la revue de presse : | | | | security, microsoft, vulnérabilité, windows, vulnerability, network, attack, google, hacker, exploit, inject, internet, remote, server, mobile, malware, apple, iphone, black, patch, sécurité, virus, linux, ebook, conficker, crypt, source, intel, virtual, facebook, access, trojan, twitter, research, firefox, overflow, pirate, phish, vista, cisco, obama, office, local, opera, adobe |
| Mini-Tagwall des Tweets de la revue Twitter : | | | | security, cisco, linux, defcon, firewall, vmware, metasploit, attack, server, phish, network, twitter, windows, exploit, nessus, botnet, backtrack, inject, crypt, wireshark, vulnerabi, python, acking, iphone, black, source, engineering, google, conficker, social, clouds, podcast, patch, vulnerability, virus, pentest, juniper, hacker, apple, client, proxy, virtual, complianc, apache, compliance |
|
|
|
|
|
|
|
|
|