IglooFTP 0.6.1, when recursively uploading a directory, allows local users to overwrite the files that are being uploaded by creating temporary files with names generated by the tmpnam function, before the files are opened by IglooFTP.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/18632 | vdb entry |
http://tigger.uic.edu/~jlongs2/holes/iglooftp.txt | exploit vendor advisory |