ws-ftp-log: WS FTP File Disclosure

日期: 2025-08-01 | 影响软件: ws-ftp-log | POC: 已公开

漏洞描述

WS_FTP software, which is a popular FTP (File Transfer Protocol) client used for transferring files between a local computer and a remote server has its log file exposed.

PoC代码[已公开]

id: ws-ftp-log

info:
  name: WS FTP File Disclosure
  author: Hardik-Solanki
  severity: low
  description: WS_FTP software, which is a popular FTP (File Transfer Protocol) client used for transferring files between a local computer and a remote server has its log file exposed.
  classification:
    cpe: cpe:2.3:a:ipswitch:ws_ftp:*:*:*:*:*:*:*:*
  metadata:
    verified: true
    max-request: 2
    vendor: ipswitch
    product: ws_ftp
    google-query: intitle:"Index of" ws_ftp.log
  tags: exposure,ftp,logs,vuln

http:
  - method: GET
    path:
      - '{{BaseURL}}/ws_ftp.log'
      - '{{BaseURL}}/WS_FTP.LOG'

    stop-at-first-match: true

    matchers-condition: and
    matchers:
      - type: regex
        regex:
          - '\d{4}\.\d{2}\.\d{2} \d{2}:\d{2} [A-Z] C:\\'
          - '\d{4}\.\d{2}\.\d{2} \d{2}:\d{2} [A-Z] D:\\'
        condition: or

      - type: status
        status:
          - 200
# digest: 4b0a00483046022100d98b985e3e4ecf3b7187538b2432ff1142d3ca7d37c9bf83bbe377b6d7c3b8830221009a7add85a78c37d3abda46ba563f91061cbcbfbdcd28c00d166c8ec447972d92:922c64590222798bb761d5b6d8e72950