ArGoSoft FTP服务器快捷方式文件上传漏洞

漏洞信息详情

ArGoSoft FTP服务器快捷方式文件上传漏洞

漏洞简介

ArGoSoft FTP是一个免费的Windows95/98/NT的FTP服务器,。

ArGoSoft FTP Server 1.4.2.7之前的版本可让远程攻击者通过上传包含快捷方式(.LNK)文件的ZIP文件,再使用SITE UNZIP将.LNK文件解压缩到服务器上,然后访问该文件来读取任意文件。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

ArGoSoft FTP Server 1.0

ArGoSoft FTP Server 1.4.2.2

http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe

ArGoSoft FTP Server 1.2.2 .2

ArGoSoft FTP Server 1.4.2.2

http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe

ArGoSoft FTP Server 1.4.1 .4

ArGoSoft FTP Server 1.4.2.2

http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe

ArGoSoft FTP Server 1.4.1 .2

ArGoSoft FTP Server 1.4.2.2

http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe

ArGoSoft FTP Server 1.4.1 .8

ArGoSoft FTP Server 1.4.2.2

http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe

ArGoSoft FTP Server 1.4.1 .5

ArGoSoft FTP Server 1.4.2.2

http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe

ArGoSoft FTP Server 1.4.1 .9

ArGoSoft FTP Server 1.4.2.2

http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe

ArGoSoft FTP Server 1.4.1 .6

ArGoSoft FTP Server 1.4.2.2

http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe

ArGoSoft FTP Server 1.4.1 .3

ArGoSoft FTP Server 1.4.2.2

http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe

ArGoSoft FTP Server 1.4.1 .1

ArGoSoft FTP Server 1.4.2.2

http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe

ArGoSoft FTP Server 1.4.1 .7

ArGoSoft FTP Server 1.4.2.2

http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe

ArGoSoft FTP Server 1.4.2 .1

ArGoSoft FTP Server 1.4.2.2

http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe

ArGoSoft FTP Server 1.4.2 .0

ArGoSoft FTP Server 1.4.2.2

http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe

参考网址

来源: www.argosoft.com

链接:http://www.argosoft.com/ftpserver/changelist.aspx

来源: SECUNIA

名称: 14172

链接:http://secunia.com/advisories/14172

来源: XF

名称: argosoft-ink-file-upload(17939)

链接:http://xforce.iss.net/xforce/xfdb/17939

来源: BID

名称: 12487

链接:http://www.securityfocus.com/bid/12487

来源: OSVDB

名称: 13614

链接:http://www.osvdb.org/13614

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享