#3762 rejected system path disclosure Juan Pablo Lopez Yacubian

The vulnerability occurs because the command "mput" lets you list the names of the files of any directory on the disc. While you can not have access to files, this can create a map of the disc.


Microsoft Windows XP [Versión 5.1.2600] (C) Copyright 1985-2001 Microsoft Corp.

C:\Documents and Settings\admin>ftp ftp> open 21 Conectado a 220 <script>alert(1)</script> Usuario ( juan 331 Password required for juan Contraseña: 230 Logged on ftp> mput Archivos locales c:\windows\*.* mput c:\windows\.? Error al abrir el archivo local c:\windows\.. mput c:\windows\..? Error al abrir el archivo local c:\windows\... mput c:\windows\$hf_mig$? Error al abrir el archivo local c:\windows\$hf_mig$. mput c:\windows\$MSI31Uninstall_KB893803v2$? Error al abrir el archivo local c:\windows\$MSI31Uninstall_KB893803v2$. mput c:\windows\$NtServicePackUninstallIDNMitigationAPIs$? Error al abrir el archivo local c:\windows\$NtServicePackUninstallIDNMitigationA PIs$. mput c:\windows\$NtServicePackUninstallNLSDownlevelMapping$? Error al abrir el archivo local c:\windows\$NtServicePackUninstallNLSDownlevelMa pping$. mput c:\windows\$NtUninstallKB835221WXP$? Error al abrir el archivo local c:\windows\$NtUninstallKB835221WXP$. mput c:\windows\$NtUninstallKB873339$? Error al abrir el archivo local c:\windows\$NtUninstallKB873339$. mput c:\windows\$NtUninstallKB885835$?

#5463 rejected system disconnects when uploading large file at slow speed Byron Zaner

When uploading a large file that will take about 22 minutes at the speed of the connection, unless you continue to open directories on the server to which you are uploading, the system disconnects from that server.

#4437 rejected syntax / parameter / documentation for command line

can anyone help me?

I'm looking for a complete documentation of command line syntax for the Filezilla Client. how can I download this?

I need parameters for the following actions: Local download folder Remote download folder Remote backup folder Filename download Filename upload File extension download File extension upload File extension download verification file Local upload folder Remote upload folder File extension upload File extension upload verification Protocol Host Login Password Use proxy Transfer Type

