Skip to content

Directory traversal #2

@cbiedl

Description

@cbiedl

Hello,
thanks for that little program, it serves me well, and I'm considering packaging it for the Debian Linux distribution.
However, there's an issue: It seems ftp-proxy has no safeguard against requesting files from outside the given base directory, in other words, "get ../../../etc/passwd" will happily deliver that file - something that shouldn't happen from a security point of view.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions