14 lines
No EOL
520 B
Text
14 lines
No EOL
520 B
Text
source: https://www.securityfocus.com/bid/11433/info
|
|
|
|
Yak! Chat Client FTP server is reported prone to a remote directory traversal vulnerability. This issue presents itself due to insufficient sanitization of user-supplied data.
|
|
|
|
This issue can ultimately allow an attacker to compromise a computer by placing malicious files on the system and executing these files through other means.
|
|
|
|
Yak! 2.1.2 and prior versions are reported vulnerable to this issue.
|
|
|
|
dir /
|
|
dir ../../windows/
|
|
|
|
put
|
|
evil.exe
|
|
../../windows/calc.exe |