OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: Re: Ipswitch WS_FTP Server 5.04 multiple arbitrary code execution vulnerabilities

michal.buckohack.pl
Date: Fri Feb 02 2007 - 17:54:04 CST


Steve,

I agree that both: iFTPAddU and iFTPAddH resemble administrator-level controls. Moreover, they are administrator-level controls. But, as ZARAZA said, the problem still remains. The successful exploitation of the issues might result in privilege escalation, therefore I called the aforementioned issues - the vulnerabilities.

kind rgds,
michal "jest" be.