SB2019060324 - Path traversal in Titan FTP Server



SB2019060324 - Path traversal in Titan FTP Server

Published: June 3, 2019 Updated: August 8, 2020

Security Bulletin ID SB2019060324
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Path traversal (CVE-ID: CVE-2019-10009)

The vulnerability allows a remote authenticated user to gain access to sensitive information.

A Directory Traversal issue was discovered in the Web GUI in Titan FTP Server 2019 Build 3505. When an authenticated user attempts to preview an uploaded file (through PreviewHandler.ashx) by using a .... technique, arbitrary files can be loaded in the server response outside the root directory.


Remediation

Install update from vendor's website.