The download_selection_recursive() function in ftplist.c for IglooFTP 0.6.1 allows remote malicious FTP servers to overwrite arbitrary files via filenames that contain / (slash) characters.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/18561 | vdb entry |
http://tigger.uic.edu/~jlongs2/holes/iglooftp2.txt | exploit vendor advisory |