Summary
This host is installed with Robo-FTP and is prone to directory traversal vulnerability.
Impact
Successful exploitation will allow attacker to download or upload arbitrary files. This may aid in further attacks.
Impact Level: Application
Solution
Upgrade to Robo-FTP version 3.7.5 or later,
For updates refer to http://www.robo-ftp.com/download/
Insight
This flaw is due to an input validation error when downloading directories containing files with directory traversal specifiers in the filename. This can be exploited to download files to an arbitrary location on a user's system.
Affected
Robo-FTP versions prior to 3.7.5.
References
Severity
Classification
-
CVE CVE-2010-4095 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities
- Adobe Acrobat and Reader PDF Handling Code Execution Vulnerability (Windows)
- Adobe AIR Multiple Vulnerabilities-01 Sep13 (Mac OS X)
- Adobe AIR Code Execution and DoS Vulnerabilities Nov13 (Windows)
- Adobe Acrobat Multiple Unspecified Vulnerabilities -01 May13 (Windows)
- Adobe AIR Multiple Vulnerabilities-01 Sep13 (Windows)