Vulnerability Scanning Solutions, LLC.
Home
Our Process
Residential
Corporate
What We Scan For
Sample Report
Client List
Terms
Contact Us
What We Scan For
Family: FTP --> Category: infos

Platinum FTP Server Vulnerability Scan


Vulnerability Scan Summary
Checks if the remote ftp server is a vulnerable version of Platinum FTP

Detailed Explanation for this Vulnerability Test

Platinum FTP server for Win32 has several vulnerabilities in
the way it checks the format of command strings passed to it.
This leads to the following vulnerabilities in the server:

The 'dir' command can be used to examine the filesystem of the machine and
gather further information about the host by using relative directory listings
(I.E. '../../../' or '\..\..\..').

The 'delete' command can be used to delete any file on the server that the
Platinum FTP server has permissions to.

Issuing the command 'cd @/..@/..' will cause the
Platinum FTP server to crash and consume all available CPU time on
the server.

*** Warning : Nessus solely relied on the banner of this server, so
*** this may be a false positive


Solution : see http://www.platinumftp.com/platinumftpserver.php
Threat Level: High

Click HERE for more information and discussions on this network vulnerability scan.

VSS, LLC.

P.O. Box 827051

Pembroke Pines, FL 33082-7051

Vulnerability Scanning Solutions, LLC.