titan ftp server version 2019 build 3505 directory traversal local file inclusion

▸▸▸ Exploit & Vulnerability >>   webapps exploit & windows vulnerability




titan ftp server version 2019 build 3505 directory traversal local file inclusion Code Code...
				
# Exploit Title: Titan FTP Server Version 2019 Build 3505 Directory Traversal/Local File Inclusion # Google Dork: N/A # Date: 3/26/2019 # Exploit Author: Kevin Randall # Vendor Homepage: https://titanftp.com/ # Software Link: https://titanftp.com/download # Version: Firmware: Titan FTP Server Version 2019 Build 3505 # Tested on: Windows 7 32 Bit # CVE : CVE-2019-10009 ********************************************************************** Discovered By: Kevin Randall on 3/23/2019 ********************************************************************** A Directory Traversal issue was discovered in the Web GUI in Titan FTP Server 2019 Build 3505. When an authenticated user attempts to preview an uploaded file (through PreviewHandler.ashx) by using a \..\..\ technique, arbitrary files can be loaded in the server response outside the root directory. *********************************************************************** Tools used: Parrot OS Windows 7 32 Bit BurpSuite Browser ************************************************************************* Vulnerability has been fixed in the following build: Build: Titan FTP Server 2019 Build 3515 ************************************************************************** Proof of Concept (PoC): Step 1: Authenticate through Titan FTP Web GUI Step 2: Upload file and attempt to view it Step 3: Intercept requests with BurpSuite when attempting to view uploaded file Step 4: Modify "path=" and "filename=" parameters in the following GET request: Ex: View contents of README.txt file in Python27 directory: Note: You can access other files in directories such as System32, Desktop etc. Payload: ***************************************************************************************** GET /PreviewHandler.ashx?path=\..\..\..\..\Python27\README.txt&filename=README.txt ***************************************************************************************** Step 5: If path is set-up correctly and if file exists, you will receive a 200 OK back from the server. Step 6: View the file through the file preview in the FTP server. ************************************************************************************************** ************************************************************************************************** Timeline: Date Discovered: 3/23/2019 Date Disclosed to Vendor: 3/23/2019 CVE Obtained: 3/24/2019 Vendor Created Patched Version Titan FTP Version 2019 Build 3515: 3/25/2019 Vendor Created Entry in Jira System for issue (SVR-499): 3/25/2019 Date Disclosed: 3/26/2019 **************************************************************************************************

Titan ftp server version 2019 build 3505 directory traversal local file inclusion Vulnerability / Exploit Source : Titan ftp server version 2019 build 3505 directory traversal local file inclusion



Last Vulnerability or Exploits

Developers

Website Vulnerability Scanner - Online Tools for Web Vulnerabilities Check Easy integrations and simple setup help you start scanning in just some minutes
Website Vulnerability Scanner - Online Tools for Web Vulnerabilities Check Discover posible vulnerabilities before GO LIVE with your project
Website Vulnerability Scanner - Online Tools for Web Vulnerabilities Check Manage your reports without any restriction

Business Owners

Website Vulnerability Scanner - Online Tools for Web Vulnerabilities Check Obtain a quick overview of your website's security information
Website Vulnerability Scanner - Online Tools for Web Vulnerabilities Check Do an audit to find and close the high risk issues before having a real damage and increase the costs
Website Vulnerability Scanner - Online Tools for Web Vulnerabilities Check Verify if your developers served you a vulnerable project or not before you are paying
Website Vulnerability Scanner - Online Tools for Web Vulnerabilities Check Run periodically scan for vulnerabilities and get info when new issues are present.

Penetration Testers

Website Vulnerability Scanner - Online Tools for Web Vulnerabilities Check Quickly checking and discover issues to your clients
Website Vulnerability Scanner - Online Tools for Web Vulnerabilities Check Bypass your network restrictions and scan from our IP for relevant results
Website Vulnerability Scanner - Online Tools for Web Vulnerabilities Check Create credible proved the real risk of vulnerabilities

Everybody

Website Vulnerability Scanner - Online Tools for Web Vulnerabilities Check If you have an website and want you check the security of site you can use our products
Website Vulnerability Scanner - Online Tools for Web Vulnerabilities Check Scan your website from any device with internet connection

Tusted by
clients

 
  Our Cyber Security Web Test application uses Cookies. By using our Cyber Security Web Test application, you are agree that we will use this information. I Accept.