WFTPD 3.00 allows remote attackers to read arbitrary files by uploading a (link) file that ends in a ".lnk." extension, which bypasses WFTPD's check for a ".lnk" extension.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/6760 | vdb entry third party advisory |
http://www.securityfocus.com/bid/2957 | patch vendor advisory exploit vdb entry third party advisory broken link |
http://www.securityfocus.com/archive/1/194442 | mailing list vdb entry third party advisory broken link |