Respuesta :
Answer:
Easy File Sharing FTP Server 3.6 Directory TraversalExplanation:
This module exploits a directory traversal vulnerability found in Easy File Sharing FTP Server Version 3.6 and Earlier. This vulnerability allows an attacker to download arbitrary files from the server by crafting a RETR command that includes file system traversal strings such as '../'
msf > use auxiliary/scanner/ftp/easy_file_sharing_ftp
msf auxiliary(easy_file_sharing_ftp) > show actions
...actions...
msf auxiliary(easy_file_sharing_ftp) > set ACTION <action-name>
msf auxiliary(easy_file_sharing_ftp) > show options
...show and set options...
msf auxiliary(easy_file_sharing_ftp) > run
The metasploit module name that can be used to exploit the CVE-2017-6510 vulnerability is called Easy File Sharing FTP Server version 3.6.
Easy File Sharing FTP Server version 3.6 is known to be opened to a directory traversal weakness or vulnerability. This makes an attacker to list and download any file from any folder outside the FTP root Directory.
This metasploit module looks through a directory traversal vulnerability found in Easy File Sharing FTP Server Version 3.6 and much more.
Conclusively, It enables an attacker to download arbitrary files from the server by coming up with an RETR command that includes file system traversal strings.