Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attackers to copy an arbitrary user's home folder via a Move action with a .. (dot dot) in the src parameter.
| Software | From | Fixed in |
|---|---|---|
| southrivertech / titan_ftp_server | 10.01.1740 | 10.01.1740.x |
| southrivertech / titan_ftp_server | - | 10.40.x |
| southrivertech / titan_ftp_server | 10.30 | 10.30.x |
| southrivertech / titan_ftp_server | 10.0.1733 | 10.0.1733.x |