tnftp “savefile” Arbitrary Command Execution
This Metasploit module exploits an arbitrary command execution vulnerability in tnftp’s handling of the resolved output filename – called “savefile” in the source – from a requested resource. If tnftp is executed without the -o command-line option, it will resolve the output filename from the last component of the requested resource. If the output filename […]
The post tnftp “savefile” Arbitrary Command Execution appeared first on MondoUnix.