mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-28 09:12:08 +00:00
1.3 KiB
1.3 KiB
CVE-2019-10009
Description
A Directory Traversal issue was discovered in the Web GUI in Titan FTP Server 2019 Build 3505. When an authenticated user attempts to preview an uploaded file (through PreviewHandler.ashx) by using a ....\ technique, arbitrary files can be loaded in the server response outside the root directory.
POC
Reference
- http://packetstormsecurity.com/files/152244/Titan-FTP-Server-2019-Build-3505-Directory-Traversal.html
- http://packetstormsecurity.com/files/152244/Titan-FTP-Server-2019-Build-3505-Directory-Traversal.html
- http://seclists.org/fulldisclosure/2019/Mar/47
- http://seclists.org/fulldisclosure/2019/Mar/47
- https://seclists.org/fulldisclosure/2019/Mar/47
- https://seclists.org/fulldisclosure/2019/Mar/47
- https://www.exploit-db.com/exploits/46611
- https://www.exploit-db.com/exploits/46611
- https://www.exploit-db.com/exploits/46611/
- https://www.exploit-db.com/exploits/46611/