
Cooolsoft PowerFTP Server 2.03은 원격 공격자가 드라이브 문자를 인수로 포함하는 ls (LIST) 명령(예: "ls C:")을 통해 임의 드라이브의 내용을 나열할 수 있도록 허용합니다.
Cooolsoft PowerFTP Server 2.03은 원격 공격자가 ls (LIST) 명령에 드라이브 문자를 인수로 포함시켜 임의 드라이브의 내용을 나열할 수 있도록 합니다. 예: "ls C:".
Securiteam 게시물: http://www.securiteam.com/exploits/6D00L2A35K.html
외부 정보: https://marc.info/?l=bugtraq&m=100698397818175&w=2
Cisco 참조: https://tools.cisco.com/security/center/viewAlert.x?alertId=2884
Alex Hernandez 일명 (@_alt3kx_)