PT-2001-2459 · Cesarftp · Cesarftp
Publicado
2001-05-27
·
Atualizado
2008-09-10
·
CVE-2001-1335
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
CesarFTP versions 0.98b and earlier
Description
A directory traversal issue allows remote authenticated users, such as anonymous, to read arbitrary files. This is achieved by sending a GET request with a filename that contains a ...%5c (modified dot dot).
Recommendations
For versions 0.98b and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Cesarftp