SB2014042907 - Multiple vulnerabilities in Titan FTP Server
Published: April 29, 2014 Updated: August 10, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 secuirty vulnerabilities.
1) Path traversal (CVE-ID: CVE-2014-1841)
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences in the web interface in Titan FTP Server before 10.40 build 1829. A remote authenticated attacker can send a specially crafted HTTP request and remote attackers to copy an arbitrary user's home folder via a Move action with a . (dot dot) in the src parameter.
2) Path traversal (CVE-ID: CVE-2014-1842)
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences in the web interface in Titan FTP Server before 10.40 build 1829. A remote authenticated attacker can send a specially crafted HTTP request and remote attackers to list all usernames via a Go action with a . (dot dot) in the search-bar value.
3) Path traversal (CVE-ID: CVE-2014-1843)
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences in the web interface in Titan FTP Server before 10.40 build 1829. A remote authenticated attacker can send a specially crafted HTTP request and remote attackers to obtain the property information of an arbitrary home folder via a Properties action with a . (dot dot) in the src parameter.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.