The mget function in cmds.c for tnftp 20030825 allows remote FTP servers to overwrite arbitrary files via FTP responses containing file names with / (slash) characters.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/18560 | vdb entry |
http://tigger.uic.edu/~jlongs2/holes/tnftp.txt | exploit vendor advisory |