Date of Discovery: 17-Nov-2009
Home FTP Server 220.127.116.11
Earlier versions may also be affected
Home FTP Server is an easy use FTP server Application. Directory Traversal Vulnerability exists in Home FTP Server that
allows an authenticated user to create directories outside the FTP root directory, which may lead to other attacks.
Home FTP Server fails to sufficiently sanitize user-supplied input in 'MKD' command. An authenticated user could use command
"MKD ../A" to create a folder named "A" outside the FTP root directory.
If you could log on the server successfully, take the following steps to create directories outside the FTP root directory:
2.sock.send("user %s\r\n" %username)
3.sock.send("pass %s\r\n" %passwd)
print ("Usage: ./expl.py