exploit-db-mirror/platforms/windows/dos/24684.txt
Offensive Security fffbf04102 Updated
2013-12-03 19:44:07 +00:00

14 lines
No EOL
532 B
Text
Executable file

source: http://www.securityfocus.com/bid/11433/info
Yak! Chat Client FTP server is reported prone to a remote directory traversal vulnerability. This issue presents itself due to insufficient sanitization of user-supplied data.
This issue can ultimately allow an attacker to compromise a computer by placing malicious files on the system and executing these files through other means.
Yak! 2.1.2 and prior versions are reported vulnerable to this issue.
dir /
dir ../../windows/
put
evil.exe
../../windows/calc.exe