WFTPD and WFTPD Pro 2.41 RC12 allows remote attackers to obtain the full pathname of the server via a "%C" command, which generates an error message that includes the pathname.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/5196 | vdb entry |
http://archives.neohapsis.com/archives/bugtraq/2000-08/0488.html | mailing list |
http://www.osvdb.org/5829 | vdb entry |