An issue in South River Technologies TitanFTP Before v2.0.1.2102 allows attackers with low-level privileges to perform Administrative actions by sending requests to the user server.
The product does not properly verify that the source of data or communication is valid.
Link | Tags |
---|---|
https://www.southrivertech.com/software/nextgen/titanftp/en/relnotes.pdf | release notes |
https://www.whiteoaksecurity.com/blog/titanftp-vulnerability-disclosure/ | third party advisory exploit |