Broker FTP server 5.9.5 for Windows NT and 9x allows a remote attacker to retrieve privileged web server system information by (1) issuing a CD command (CD C:) followed by the LS command, (2) specifying arbitrary paths in the UNC format (\\computername\sharename).
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/6674 | vdb entry |
http://www.securityfocus.com/bid/2853 | vdb entry vendor advisory |
http://www.securityfocus.com/archive/1/190032 | mailing list exploit vendor advisory |