Home page logo

bugtraq logo Bugtraq mailing list archives

PhpWebFTP 3.2 Login Script
From: arko.dhar () gmail com
Date: 17 Apr 2006 02:21:52 -0000

phpWebFTP enables connections to FTP servers, even behind a firewall not allowing traffic. phpWebFTP bypasses the 
firewall by making a FTP connection from your webserver to the FTP server and transfering the files to your webclient 
over the http protocol


Issue :
Well I have found that most of the sites that use phpwebftp v3.2 > less  have a problem. The user login script is a 
javascript file called script.js. This file validates the user input in the logon box. But to my surprise this file is 
directly accessed by web browser . The  disclosure of the source code can help an attacker to trigger    code 
injections .

Exploit :

Further a directory traversal is possible via malicious arguments passed on the web browser using POST Method relative 
to the path of phpWebftp ie. http://www.anysite.com/PhpWebFtp/index.php? .


  By Date           By Thread  

Current thread:
  • PhpWebFTP 3.2 Login Script arko . dhar (Apr 17)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]