VRDA Feed by JPCERT/CC
  Vulnerability Response Decision Assistance Feed : Information for vulnerability impact analysis
[ about VRDA Feed | JPCERT/CC



 
Vulnerability Analysis Result (Revision No : 1) [ Download XML
CVE-2010-2425
titan_ftp_server: Directory traversal vulnerability in TitanFTPd in S...
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2425

Original

Directory traversal vulnerability in TitanFTPd in South River Technologies Titan FTP Server 8.10.1125, and probably earlier versions, allows remote authenticated users to read or delete arbitrary files via "..//" sequences in a COMB command.

Translation   (Show)





About This Analysis Information
Analysis Information Provider:
NIST NVD
First Published:
2010-06-24
Source Information Category:
Advisory, Alert
Last Updated:
2010-06-24




Affected Product Tags
cpe:/a:southrivertech:titan_ftp_server:1.0.17
cpe:/a:southrivertech:titan_ftp_server:1.0.18
cpe:/a:southrivertech:titan_ftp_server:1.0.19
cpe:/a:southrivertech:titan_ftp_server:1.0.20
cpe:/a:southrivertech:titan_ftp_server:1.0.21
cpe:/a:southrivertech:titan_ftp_server:1.0.22
cpe:/a:southrivertech:titan_ftp_server:1.0.23
cpe:/a:southrivertech:titan_ftp_server:1.0.24
cpe:/a:southrivertech:titan_ftp_server:1.0.25
cpe:/a:southrivertech:titan_ftp_server:1.0.26
cpe:/a:southrivertech:titan_ftp_server:1.0.27
cpe:/a:southrivertech:titan_ftp_server:1.0.28
cpe:/a:southrivertech:titan_ftp_server:1.0.29
cpe:/a:southrivertech:titan_ftp_server:1.0.30
cpe:/a:southrivertech:titan_ftp_server:1.0.31
cpe:/a:southrivertech:titan_ftp_server:1.1.33
cpe:/a:southrivertech:titan_ftp_server:1.11.34
cpe:/a:southrivertech:titan_ftp_server:2.0.44:beta
cpe:/a:southrivertech:titan_ftp_server:2.00.95
cpe:/a:southrivertech:titan_ftp_server:2.01.96
cpe:/a:southrivertech:titan_ftp_server:2.02.99
cpe:/a:southrivertech:titan_ftp_server:2.10.119
cpe:/a:southrivertech:titan_ftp_server:2.10.120
cpe:/a:southrivertech:titan_ftp_server:2.10.121
cpe:/a:southrivertech:titan_ftp_server:2.11.132
cpe:/a:southrivertech:titan_ftp_server:2.20.140
cpe:/a:southrivertech:titan_ftp_server:2.21.142
cpe:/a:southrivertech:titan_ftp_server:2.30.151
cpe:/a:southrivertech:titan_ftp_server:2.31.152
cpe:/a:southrivertech:titan_ftp_server:2.40.155
cpe:/a:southrivertech:titan_ftp_server:3.00.162
cpe:/a:southrivertech:titan_ftp_server:3.01.163
cpe:/a:southrivertech:titan_ftp_server:3.02.165
cpe:/a:southrivertech:titan_ftp_server:3.10.169
cpe:/a:southrivertech:titan_ftp_server:3.12.172
cpe:/a:southrivertech:titan_ftp_server:3.20.175
cpe:/a:southrivertech:titan_ftp_server:3.21.177
cpe:/a:southrivertech:titan_ftp_server:3.22.178
cpe:/a:southrivertech:titan_ftp_server:3.30.186
cpe:/a:southrivertech:titan_ftp_server:4.00.245
cpe:/a:southrivertech:titan_ftp_server:4.01.246
cpe:/a:southrivertech:titan_ftp_server:4.02.248
cpe:/a:southrivertech:titan_ftp_server:4.03.249
cpe:/a:southrivertech:titan_ftp_server:4.05.252
cpe:/a:southrivertech:titan_ftp_server:4.10.256
cpe:/a:southrivertech:titan_ftp_server:4.11.257
cpe:/a:southrivertech:titan_ftp_server:4.13.260
cpe:/a:southrivertech:titan_ftp_server:4.14.261
cpe:/a:southrivertech:titan_ftp_server:4.20.263
cpe:/a:southrivertech:titan_ftp_server:4.21.264
cpe:/a:southrivertech:titan_ftp_server:4.22.265
cpe:/a:southrivertech:titan_ftp_server:4.23.266
cpe:/a:southrivertech:titan_ftp_server:4.30.269
cpe:/a:southrivertech:titan_ftp_server:4.31.272
cpe:/a:southrivertech:titan_ftp_server:5.00.303
cpe:/a:southrivertech:titan_ftp_server:5.01.306
cpe:/a:southrivertech:titan_ftp_server:5.02.307
cpe:/a:southrivertech:titan_ftp_server:5.03.308
cpe:/a:southrivertech:titan_ftp_server:5.03.309
cpe:/a:southrivertech:titan_ftp_server:5.03.310
cpe:/a:southrivertech:titan_ftp_server:5.04.311
cpe:/a:southrivertech:titan_ftp_server:5.04.312
cpe:/a:southrivertech:titan_ftp_server:5.04.313
cpe:/a:southrivertech:titan_ftp_server:5.04.314
cpe:/a:southrivertech:titan_ftp_server:5.04.315
cpe:/a:southrivertech:titan_ftp_server:5.05.316
cpe:/a:southrivertech:titan_ftp_server:5.05.317
cpe:/a:southrivertech:titan_ftp_server:5.05.318
cpe:/a:southrivertech:titan_ftp_server:5.05.319
cpe:/a:southrivertech:titan_ftp_server:5.05.320
cpe:/a:southrivertech:titan_ftp_server:5.05.321
cpe:/a:southrivertech:titan_ftp_server:5.05.322
cpe:/a:southrivertech:titan_ftp_server:5.05.323
cpe:/a:southrivertech:titan_ftp_server:5.05.324
cpe:/a:southrivertech:titan_ftp_server:5.05.325
cpe:/a:southrivertech:titan_ftp_server:5.05.326
cpe:/a:southrivertech:titan_ftp_server:5.05.327
cpe:/a:southrivertech:titan_ftp_server:5.10.328
cpe:/a:southrivertech:titan_ftp_server:5.10.329
cpe:/a:southrivertech:titan_ftp_server:5.11.330
cpe:/a:southrivertech:titan_ftp_server:5.11.331
cpe:/a:southrivertech:titan_ftp_server:5.12.332
cpe:/a:southrivertech:titan_ftp_server:5.12.333
cpe:/a:southrivertech:titan_ftp_server:5.12.334
cpe:/a:southrivertech:titan_ftp_server:5.12.335
cpe:/a:southrivertech:titan_ftp_server:5.12.336
cpe:/a:southrivertech:titan_ftp_server:5.20.342
cpe:/a:southrivertech:titan_ftp_server:5.21.347
cpe:/a:southrivertech:titan_ftp_server:5.22.350
cpe:/a:southrivertech:titan_ftp_server:5.23.351
cpe:/a:southrivertech:titan_ftp_server:5.24.352
cpe:/a:southrivertech:titan_ftp_server:5.25.356
cpe:/a:southrivertech:titan_ftp_server:5.26.361
cpe:/a:southrivertech:titan_ftp_server:5.27.362
cpe:/a:southrivertech:titan_ftp_server:5.30.367
cpe:/a:southrivertech:titan_ftp_server:5.31.373
cpe:/a:southrivertech:titan_ftp_server:5.32.376
cpe:/a:southrivertech:titan_ftp_server:5.33.380
cpe:/a:southrivertech:titan_ftp_server:5.33.381
cpe:/a:southrivertech:titan_ftp_server:5.35.385
cpe:/a:southrivertech:titan_ftp_server:5.36.386
cpe:/a:southrivertech:titan_ftp_server:5.37.387
cpe:/a:southrivertech:titan_ftp_server:5.38.388
cpe:/a:southrivertech:titan_ftp_server:5.39.389
cpe:/a:southrivertech:titan_ftp_server:6.00.492
cpe:/a:southrivertech:titan_ftp_server:6.01.512
cpe:/a:southrivertech:titan_ftp_server:6.03.537
cpe:/a:southrivertech:titan_ftp_server:6.04.545
cpe:/a:southrivertech:titan_ftp_server:6.05.550
cpe:/a:southrivertech:titan_ftp_server:6.06.555
cpe:/a:southrivertech:titan_ftp_server:6.10.560
cpe:/a:southrivertech:titan_ftp_server:6.20.587
cpe:/a:southrivertech:titan_ftp_server:6.21.596
cpe:/a:southrivertech:titan_ftp_server:6.23.616
cpe:/a:southrivertech:titan_ftp_server:6.24.621
cpe:/a:southrivertech:titan_ftp_server:6.25.622
cpe:/a:southrivertech:titan_ftp_server:6.26.630
cpe:/a:southrivertech:titan_ftp_server:7.00
cpe:/a:southrivertech:titan_ftp_server:7.01
cpe:/a:southrivertech:titan_ftp_server:7.02
cpe:/a:southrivertech:titan_ftp_server:7.10
cpe:/a:southrivertech:titan_ftp_server:7.12
cpe:/a:southrivertech:titan_ftp_server:8.00
cpe:/a:southrivertech:titan_ftp_server:8.01
cpe:/a:southrivertech:titan_ftp_server:8.10
cpe:/a:southrivertech:titan_ftp_server:8.10.1125 and previous versions
 


Vulnerability Analysis Results
[Access Vector]  [?]
Undefined [?]

Local [?]
Adjacent Network [?]
X Network [?]

[Access Complexit]  [?]
Undefined [?]

High [?]
Medium [?]
X Low [?]

[Authentication]  [?]
Undefined [?]

Multiple [?]
X Single [?]
None [?]

[Confidentiality Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

[Integrity Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

[Availability Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

Alternatives




References
BID 40949




BUGTRAQ 20100617 TitanFTP Server COMB directory traversal




OSVDB 65622




SECUNIA 40237




Vulnerability Type Path Traversal (CWE-22)





Copyright © 2010 JPCERT/CC All Rights Reserved.