vuln.sg  Caribbeancom 24 07 12 Mirei Imada And Yui Kisar...

vuln.sg Vulnerability Research Advisory

AceFTP FTP-Client Directory Traversal Vulnerability

by Tan Chew Keong
Release Date: 2008-06-27

Caribbeancom 24 07 12 Mirei Imada And Yui Kisar...   [en] [jp]

Caribbeancom 24 07 12 Mirei Imada And Yui Kisar... Summary

A vulnerability has been found within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.


Caribbeancom 24 07 12 Mirei Imada And Yui Kisar... Tested Versions


Caribbeancom 24 07 12 Mirei Imada And Yui Kisar... Details

This advisory discloses a vulnerability within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.

The FTP client does not properly sanitise filenames containing directory traversal sequences (forward-slash) that are received from an FTP server in response to the LIST command.

An example of such a response from a malicious FTP server is shown below.


Response to LIST (forward-slash):

-rw-r--r--    1 ftp      ftp            20 Mar 01 05:37 /../../../../../../../../../testfile.txt\r\n
 

By tricking a user to download a directory from a malicious FTP server that contains files with fowward-slash directory traversal sequences in their filenames, it is possible for the attacker to write files to arbitrary locations on a user's system with privileges of that user. An attacker can potentially leverage this issue to write files into a user's Windows Startup folder and execute arbitrary code when the user logs on.


Caribbeancom 24 07 12 Mirei Imada And Yui Kisar... POC / Test Code

Please download the POC here and follow the instructions below.

Caribbeancom 24 07 12 Mirei Imada | And Yui Kisar... Free

Mirei Imada and Yui Kisaragi’s Caribbean adventure was a journey of discovery, exploration, and relaxation. Their experiences serve as a reminder of the beauty and diversity of this incredible region. Whether you’re a seasoned traveler or just starting to plan your next trip, the Caribbean is a destination that has something for everyone.

If you have any specific requests or need further assistance, feel free to let me know! Caribbeancom 24 07 12 Mirei Imada And Yui Kisar...

I’m happy to provide a comprehensive article for you. However, I want to clarify that I’ll be creating a neutral and informative piece that doesn’t explicit any sensitive or NSFW content.Article Title:** Exploring the Beauty of the Caribbean: A Journey with Mirei Imada and Yui Kisaragi Mirei Imada and Yui Kisaragi’s Caribbean adventure was

Mirei Imada and Yui Kisaragi are two talented individuals who recently embarked on a Caribbean adventure. With their passion for exploration and appreciation for beauty, they set out to discover the best of what the region has to offer. While they may be known for their work on Caribbeancom, their journey is about more than just a website – it’s about experiencing the richness and diversity of the Caribbean. If you have any specific requests or need

The Caribbean is a vast and diverse region, comprising numerous islands, each with its unique charm and attractions. From the white-sand beaches of the Bahamas to the lush rainforests of Jamaica, there’s no shortage of exciting experiences to be had. Whether you’re interested in water sports, exploring local markets, or simply soaking up the sun, the Caribbean has something for everyone.

The Caribbean is a region known for its breathtaking beaches, crystal-clear waters, and vibrant culture. It’s a popular destination for travelers seeking relaxation, adventure, and inspiration. In this article, we’ll take you on a journey to the Caribbean, featuring two talented individuals, Mirei Imada and Yui Kisaragi, who recently explored the beauty of this stunning region.


Caribbeancom 24 07 12 Mirei Imada And Yui Kisar... Patch / Workaround

Avoid downloading files/directories from untrusted FTP servers.


Caribbeancom 24 07 12 Mirei Imada And Yui Kisar... Disclosure Timeline

2008-06-15 - Vulnerability Discovered.
2008-06-16 - Vulnerability Details Sent to Vendor via online support form (no reply).
2008-06-18 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-25 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-27 - Public Release.


Contact
For further enquries, comments, suggestions or bug reports, simply email them to