PT-2001-1863 · Qpc+1 · Qpc Qvt/Net+1

Publicado

2001-09-20

·

Atualizado

2017-10-10

·

CVE-2001-0680

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: QPC QVT/Net version 4.0 AVT/Term version 5.0
Description: A directory traversal issue exists in the ftpd component, allowing a remote attacker to traverse directories on the server using a "dot dot" attack in a LIST (ls) command.
Recommendations: For QPC QVT/Net version 4.0, restrict access to the ftpd component until a fix is available. For AVT/Term version 5.0, consider disabling the LIST (ls) command functionality in the ftpd component as a temporary workaround.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2001-0680

Produtos afetados

Avt/Term
Qpc Qvt/Net