by Tan Chew Keong
Release Date: 2008-06-27
[en] [jp]
Summary
A vulnerability has been found within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.
Tested Versions
Details
This advisory discloses a vulnerability within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.
The FTP client does not properly sanitise filenames containing directory traversal sequences (forward-slash) that are received from an FTP server in response to the LIST command.
An example of such a response from a malicious FTP server is shown below.
Response to LIST (forward-slash):
-rw-r--r-- 1 ftp ftp 20 Mar 01 05:37 /../../../../../../../../../testfile.txt\r\n
By tricking a user to download a directory from a malicious FTP server that contains files with fowward-slash directory traversal sequences in their filenames, it is possible for the attacker to write files to arbitrary locations on a user's system with privileges of that user. An attacker can potentially leverage this issue to write files into a user's Windows Startup folder and execute arbitrary code when the user logs on.
POC / Test Code
Please download the POC here and follow the instructions below.
Nicolette Shea Dont Bring Your Sister Around M Free May 2026
In a world where women's bodies and choices are often policed, Shea's message is a breath of fresh air. She's unapologetically herself, refusing to conform to societal expectations or compromise her values. Her freedom is a testament to the power of self-acceptance and the importance of prioritizing one's own needs and desires.
Nicolette Shea's decision to embrace her true self has been a liberating experience, one that has allowed her to live life on her own terms. Her confidence and self-acceptance have inspired countless fans and followers, who see her as a role model for self-expression. Shea's message is simple: don't let others dictate your path; forge your own way. nicolette shea dont bring your sister around m free
In a recent interview, Shea expanded on her statement, "Don't bring your sister around me, I'm free." She explained that this phrase was not about excluding others, but about creating a space for herself to be free from judgment and expectation. "I'm not saying that I don't value relationships or connections with others," she clarified. "However, I need to prioritize my own needs and desires. If that means taking a step back from certain relationships or situations, then so be it." In a world where women's bodies and choices
Nicolette Shea's statement, "Don't bring your sister around me, I'm free," is more than just a phrase – it's a way of life. It's a reminder that we have the power to create our own reality, to forge our own path, and to prioritize our own needs and desires. For those who feel suffocated by societal expectations or trapped in toxic relationships, Shea's message is a beacon of hope. Nicolette Shea's decision to embrace her true self
For many, Nicolette Shea's statement resonates deeply. We've all been there – stuck in toxic relationships or situations that drain our energy and compromise our values. Shea's message is a reminder that we have the power to break free from these dynamics. We don't have to conform to societal expectations or tolerate behavior that doesn't serve us.
For Nicolette Shea, freedom is not just a state of mind; it's a way of life. Born and raised in a traditional household, she was expected to follow a certain path, one that was predetermined by her family and society. However, she had other plans. Shea's journey to self-discovery was not without its challenges. Growing up, she struggled with the idea of conforming to societal norms, feeling suffocated by the expectations placed upon her.
Patch / Workaround
Avoid downloading files/directories from untrusted FTP servers.
Disclosure Timeline
2008-06-15 - Vulnerability Discovered.
2008-06-16 - Vulnerability Details Sent to Vendor via online support form (no reply).
2008-06-18 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-25 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-27 - Public Release.