SB2014042907 - Multiple vulnerabilities in Titan FTP Server



SB2014042907 - Multiple vulnerabilities in Titan FTP Server

Published: April 29, 2014 Updated: August 10, 2020

Security Bulletin ID SB2014042907
Severity
Medium
Patch available
NO
Number of vulnerabilities 3
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 secuirty vulnerabilities.


1) Path traversal (CVE-ID: CVE-2014-1841)

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences in the web interface in Titan FTP Server before 10.40 build 1829. A remote authenticated attacker can send a specially crafted HTTP request and remote attackers to copy an arbitrary user's home folder via a Move action with a . (dot dot) in the src parameter.


2) Path traversal (CVE-ID: CVE-2014-1842)

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences in the web interface in Titan FTP Server before 10.40 build 1829. A remote authenticated attacker can send a specially crafted HTTP request and remote attackers to list all usernames via a Go action with a . (dot dot) in the search-bar value.


3) Path traversal (CVE-ID: CVE-2014-1843)

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences in the web interface in Titan FTP Server before 10.40 build 1829. A remote authenticated attacker can send a specially crafted HTTP request and remote attackers to obtain the property information of an arbitrary home folder via a Properties action with a . (dot dot) in the src parameter.


Remediation

Cybersecurity Help is not aware of any official remediation provided by the vendor.