This host is installed with 3D FTP Client and is prone to directory traversal vulnerability.
Successful exploitation will allow attackers to write files into a user's Startup folder to execute malicious code when the user logs on. Impact Level: Application.
Upgrade to version 9.03 or later, For updates refer to http://3dftp.com/download_3dftp.htm
The flaw exists due to an error in handling of certain crafted file names. It does not properly sanitise filenames containing directory traversal sequences that are received from an FTP server.
3D FTP Client 9.0 build 2 (9.0.2) and prior.
- Serv-U Web Client HTTP Request Remote Buffer Overflow Vulnerability
- Quick 'n Easy FTP Login Denial of Service Vulnerability
- wu-ftpd SITE EXEC vulnerability
- RhinoSoft Serv-U FTP Server TEA Decoder Remote Stack Buffer Overflow Vulnerability
- Open and Compact FTPD Auth Bypass and Directory Traversal Vulnerabilities