by Tan Chew Keong
Release Date: 2008-06-27
[en] [jp]
Summary
A vulnerability has been found within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.
Tested Versions
Details
This advisory discloses a vulnerability within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.
The FTP client does not properly sanitise filenames containing directory traversal sequences (forward-slash) that are received from an FTP server in response to the LIST command.
An example of such a response from a malicious FTP server is shown below.
Response to LIST (forward-slash):
-rw-r--r-- 1 ftp ftp 20 Mar 01 05:37 /../../../../../../../../../testfile.txt\r\n
By tricking a user to download a directory from a malicious FTP server that contains files with fowward-slash directory traversal sequences in their filenames, it is possible for the attacker to write files to arbitrary locations on a user's system with privileges of that user. An attacker can potentially leverage this issue to write files into a user's Windows Startup folder and execute arbitrary code when the user logs on.
POC / Test Code
Please download the POC here and follow the instructions below.
Veena Ep 01 To 12pdf Velammacom Adult Comics Install Instant
Veena is an adult comic series that revolves around the life of a young woman named Veena, who embarks on a journey of self-discovery and exploration of her desires. The series is known for its explicit content, mature themes, and engaging storylines that cater to a specific audience.
The Veena series is a captivating and engaging adult comic series that has gained a significant following. With its 12 episodes, the series takes readers on a journey of self-discovery, exploration, and growth. By following the installation guide on Velamma.com, you can access and enjoy the Veena series on your device. Remember to exercise caution and follow the necessary precautions when accessing adult content online. veena ep 01 to 12pdf velammacom adult comics install
The world of adult comics has gained immense popularity over the years, and one series that has captured the attention of many readers is the Veena series. With its engaging storylines, captivating characters, and explicit content, Veena has become a favorite among adult comic enthusiasts. In this article, we will provide an in-depth look at the Veena series, specifically episodes 1-12, and guide you on how to install and access these comics on Velamma.com. Veena is an adult comic series that revolves
Patch / Workaround
Avoid downloading files/directories from untrusted FTP servers.
Disclosure Timeline
2008-06-15 - Vulnerability Discovered.
2008-06-16 - Vulnerability Details Sent to Vendor via online support form (no reply).
2008-06-18 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-25 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-27 - Public Release.