Summary
This host is installed with 3D FTP Client and is prone to directory traversal vulnerability.
Impact
Successful exploitation will allow attackers to write files into a user's Startup folder to execute malicious code when the user logs on.
Impact Level: Application.
Solution
Upgrade to version 9.03 or later,
For updates refer to http://3dftp.com/download_3dftp.htm
Insight
The flaw exists due to an error in handling of certain crafted file names. It does not properly sanitise filenames containing directory traversal sequences that are received from an FTP server.
Affected
3D FTP Client 9.0 build 2 (9.0.2) and prior.
References
Severity
Classification
-
CVE CVE-2010-3102 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities
- TYPSoft FTP Server Multiple Commands Remote Denial of Service Vulnerabilities
- SolarFTP PASV Command Remote Denial of Service Vulnerability
- AutoFTP Manager FTP Client Directory Traversal Vulnerability
- pyftpdlib FTP Server Multiple Vulnerabilities
- KnFTPd FTP Server Multiple Commands Remote Buffer Overflow Vulnerabilities