Crob FTP Server 3.5.1 - Remote Information Disclosure
Author: Zero X
type: remote
platform: windows
port:
date_added: 2004-02-02
date_updated: 2012-12-24
verified: 1
codes: CVE-2004-2309;OSVDB-3806
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/9546/info
A vulnerability has been reported in the Crob FTP server, which occurs due to a lack of validation of input from the user. By issuing a specially crafted request, a malevolent user may be able to gain access to files outside of the ftp root directory.
You can read all directories on the system with the following command:
dir ../../../../../*